General Info

File name

rs.exe

Full analysis
https://app.any.run/tasks/b2915307-865a-4e7d-a8df-b4d689e13511
Verdict
Malicious activity
Analysis date
11/8/2018, 20:30:20
OS:
Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:

ransomware

gandcrab

Indicators:

MIME:
application/x-dosexec
File info:
PE32 executable (GUI) Intel 80386, for MS Windows
MD5

6c02819d4c8f9dd920e0368588e65ccb

SHA1

59b2862e85e0f030f18a7d0c07fb2dca2d5b2432

SHA256

b0fbcec8c22a53492e24e3cd38e32af4f2d3399b1ef71f6cef6d58bc692957f1

SSDEEP

1536:52YN1nS9cCY6Vbs8P+TLtXBcGVyThYhqi0sWjcdhIS3FZBq2dks4QTg12A58AQpE:xNQDVQ8ujb1hhhIS3FZBaCgrQp0Mq

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distored by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.

Software environment set and analysis options

Launch configuration

Task duration
60 seconds
Additional time used
none
Fakenet option
off
Heavy Evaision option
off
MITM proxy
off
Route via Tor
off
Network geolocation
off
Privacy
Public submission
Autoconfirmation of UAC
on

Software preset

  • Internet Explorer 8.0.7601.17514
  • Adobe Acrobat Reader DC MUI (15.023.20070)
  • Adobe Flash Player 26 ActiveX (26.0.0.131)
  • Adobe Flash Player 26 NPAPI (26.0.0.131)
  • Adobe Flash Player 26 PPAPI (26.0.0.131)
  • Adobe Refresh Manager (1.8.0)
  • CCleaner (5.35)
  • FileZilla Client 3.36.0 (3.36.0)
  • Google Chrome (68.0.3440.106)
  • Google Update Helper (1.3.33.17)
  • Java 8 Update 92 (8.0.920.14)
  • Java Auto Updater (2.8.92.14)
  • Microsoft .NET Framework 4.6.1 (4.6.01055)
  • Microsoft Office Access MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Access Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office OneNote MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Outlook MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office PowerPoint MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Professional 2010 (14.0.6029.1000)
  • Microsoft Office Proof (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (French) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Spanish) 2010 (14.0.6029.1000)
  • Microsoft Office Proofing (English) 2010 (14.0.6029.1000)
  • Microsoft Office Publisher MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Single Image 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (9.0.30729.6161)
  • Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (10.0.40219)
  • Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (12.0.30501.0)
  • Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2017 Redistributable (x86) - 14.15.26706 (14.15.26706.0)
  • Microsoft Visual C++ 2017 x86 Additional Runtime - 14.15.26706 (14.15.26706)
  • Microsoft Visual C++ 2017 x86 Minimum Runtime - 14.15.26706 (14.15.26706)
  • Mozilla Firefox 61.0.2 (x86 en-US) (61.0.2)
  • Notepad++ (32-bit x86) (7.5.1)
  • Opera 12.15 (12.15.1748)
  • Skype version 8.29 (8.29)
  • VLC media player (2.2.6)
  • WinRAR 5.60 (32-bit) (5.60.0)

Hotfixes

  • Client LanguagePack Package
  • Client Refresh LanguagePack Package
  • CodecPack Basic Package
  • Foundation Package
  • IE Troubleshooters Package
  • InternetExplorer Optional Package
  • KB2534111
  • KB2999226
  • KB976902
  • LocalPack AU Package
  • LocalPack CA Package
  • LocalPack GB Package
  • LocalPack US Package
  • LocalPack ZA Package
  • ProfessionalEdition
  • UltimateEdition

Behavior activities

MALICIOUS SUSPICIOUS INFO
Actions looks like stealing of personal data
  • rs.exe (PID: 3776)
GandCrab keys found
  • rs.exe (PID: 3776)
Writes file to Word startup folder
  • rs.exe (PID: 3776)
Deletes shadow copies
  • rs.exe (PID: 3776)
Dropped file may contain instructions of ransomware
  • rs.exe (PID: 3776)
Renames files like Ransomware
  • rs.exe (PID: 3776)
Detected GandCrab ransomware
  • rs.exe (PID: 3776)
Creates files like Ransomware instruction
  • rs.exe (PID: 3776)
Creates files in the user directory
  • rs.exe (PID: 3776)
Dropped object may contain TOR URL's
  • rs.exe (PID: 3776)

Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Static information

TRiD
.exe
|   Win32 Executable MS Visual C++ (generic) (42.2%)
.exe
|   Win64 Executable (generic) (37.3%)
.dll
|   Win32 Dynamic Link Library (generic) (8.8%)
.exe
|   Win32 Executable (generic) (6%)
.exe
|   Generic Win/DOS Executable (2.7%)
EXIF
EXE
MachineType:
Intel 386 or later, and compatibles
TimeStamp:
2018:08:01 01:51:50+02:00
PEType:
PE32
LinkerVersion:
12
CodeSize:
58880
InitializedDataSize:
78848
UninitializedDataSize:
null
EntryPoint:
0x41a1
OSVersion:
5.1
ImageVersion:
null
SubsystemVersion:
5.1
Subsystem:
Windows GUI
Summary
Architecture:
IMAGE_FILE_MACHINE_I386
Subsystem:
IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date:
31-Jul-2018 23:51:50
Detected languages
English - United States
DOS Header
Magic number:
MZ
Bytes on last page of file:
0x0090
Pages in file:
0x0003
Relocations:
0x0000
Size of header:
0x0004
Min extra paragraphs:
0x0000
Max extra paragraphs:
0xFFFF
Initial SS value:
0x0000
Initial SP value:
0x00B8
Checksum:
0x0000
Initial IP value:
0x0000
Initial CS value:
0x0000
Overlay number:
0x0000
OEM identifier:
0x0000
OEM information:
0x0000
Address of NE header:
0x000000F0
PE Headers
Signature:
PE
Machine:
IMAGE_FILE_MACHINE_I386
Number of sections:
5
Time date stamp:
31-Jul-2018 23:51:50
Pointer to Symbol Table:
0x00000000
Number of symbols:
0
Size of Optional Header:
0x00E0
Characteristics
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
Sections
Name Virtual Address Virtual Size Raw Size Charateristics Entropy
.text 0x00001000 0x0000E444 0x0000E600 IMAGE_SCN_CNT_CODE,IMAGE_SCN_MEM_EXECUTE,IMAGE_SCN_MEM_READ 6.59982
.rdata 0x00010000 0x00005DD2 0x00005E00 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ 4.53877
.data 0x00016000 0x0000C1F4 0x0000A600 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 4.02306
.rsrc 0x00023000 0x000001E0 0x00000200 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ 4.71134
.reloc 0x00024000 0x00001030 0x00001200 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_DISCARDABLE,IMAGE_SCN_MEM_READ 6.33166
Resources
1

Imports
    KERNEL32.dll

    USER32.dll

    ADVAPI32.dll

    SHELL32.dll

    MPR.dll

    WININET.dll

Exports

    No exports.

Screenshots

Processes

Total processes
35
Monitored processes
2
Malicious processes
1
Suspicious processes
0

Behavior graph

+
start #GANDCRAB rs.exe wmic.exe no specs
Specs description
Program did not start
Integrity level elevation
Task сontains an error or was rebooted
Process has crashed
Task contains several apps running
Executable file was dropped
Debug information is available
Process was injected
Network attacks were detected
Application downloaded the executable file
Actions similar to stealing personal data
Behavior similar to exploiting the vulnerability
Inspected object has sucpicious PE structure
File is detected by antivirus software
CPU overrun
RAM overrun
Process starts the services
Process was added to the startup
Behavior similar to spam
Low-level access to the HDD
Probably Tor was used
System was rebooted
Connects to the network
Known threat

Process information

Click at the process to see the details.

PID
3776
CMD
"C:\Users\admin\AppData\Local\Temp\rs.exe"
Path
C:\Users\admin\AppData\Local\Temp\rs.exe
Indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Version:
Company
Description
Version
Modules
Image
c:\users\admin\appdata\local\temp\rs.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\mpr.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\profapi.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\cryptsp.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\version.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\userenv.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\schannel.dll
c:\windows\system32\credssp.dll
c:\windows\system32\secur32.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\drprov.dll
c:\windows\system32\winsta.dll
c:\windows\system32\ntlanman.dll
c:\windows\system32\davclnt.dll
c:\windows\system32\davhlpr.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\netutils.dll
c:\windows\system32\browcli.dll
c:\windows\system32\propsys.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\wbem\wmic.exe

PID
2092
CMD
"C:\Windows\system32\wbem\wmic.exe" shadowcopy delete
Path
C:\Windows\system32\wbem\wmic.exe
Indicators
No indicators
Parent process
rs.exe
User
admin
Integrity Level
MEDIUM
Exit code
2147749908
Version:
Company
Microsoft Corporation
Description
WMI Commandline Utility
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\wbem\wmic.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\framedynos.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\secur32.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\wbem\wbemprox.dll
c:\windows\system32\wbemcomn.dll
c:\windows\system32\msxml3.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\program files\common files\microsoft shared\office14\msoxmlmf.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\windows\system32\wbem\wbemsvc.dll
c:\windows\system32\wbem\fastprox.dll
c:\windows\system32\ntdsapi.dll
c:\windows\system32\wbem\wmiutils.dll

Registry activity

Total events
117
Read events
87
Write events
30
Delete events
0

Modification events

PID
Process
Operation
Key
Name
Value
3776
rs.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\rs_RASAPI32
EnableFileTracing
0
3776
rs.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\rs_RASAPI32
EnableConsoleTracing
0
3776
rs.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\rs_RASAPI32
FileTracingMask
4294901760
3776
rs.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\rs_RASAPI32
ConsoleTracingMask
4294901760
3776
rs.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\rs_RASAPI32
MaxFileSize
1048576
3776
rs.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\rs_RASAPI32
FileDirectory
%windir%\tracing
3776
rs.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\rs_RASMANCS
EnableFileTracing
0
3776
rs.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\rs_RASMANCS
EnableConsoleTracing
0
3776
rs.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\rs_RASMANCS
FileTracingMask
4294901760
3776
rs.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\rs_RASMANCS
ConsoleTracingMask
4294901760
3776
rs.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\rs_RASMANCS
MaxFileSize
1048576
3776
rs.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\rs_RASMANCS
FileDirectory
%windir%\tracing
3776
rs.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
3776
rs.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
4600000069000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
3776
rs.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
3776
rs.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
3776
rs.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
LanguageList
en-US
3776
rs.exe
write
HKEY_CURRENT_USER\Software\keys_data\data
public
0602000000A40000525341310008000001000100AFF3B6874E1B70F2663B7F33C7F237D89AE1C74BE441D9F1A70D3AF4571D652A7416E272F8E206A24D8C2AF95AA9276DE858C422FD04179E4E5D795E5036A4864C5DB2ABEF2B5E13469E10FDEBB1E8CDC1FD57DDF48DCB2278C3749C6AF01BD8D22CFEB5DA76E23C668196F941FAA5636B9DD85007F3BDC4B89093344E52B8567903309A57528956FDF16E987827E3716CB45101ED070C720C88241584A638D0D40BB5FC05B5089BB80C9B076D20BBD7070A4FBD5D5BFC1022F9AAAD50462731C99BDC5B9CB2A600AB188149001305678E61472CC6944A14F8C69E52C5334C5BD7FD5664518E377344F5CF6716CE90D756FC0FE1146ACE7E0E6C85CB62A33EC8
3776
rs.exe
write
HKEY_CURRENT_USER\Software\keys_data\data
private
94040000022ABA12BFB2C5FCF64C10586F8E8B59613BAFA6A26FB52D2B97E61B50A8B89A875196B7B2F06B81746FABAEC85B52BF28903991616B3EB6401F095279B42FE7FC0691021B75B49681D4598BCB5C22E01A9789A122BD1891471438E96568AB7C740167F832A5603BED23200BEA53BC28073107770BEB4FBFED7E31BEBB99C884177E4C6966951F20CD6EC3BBB5BB2540507E6CAB4E87CCCD85A5771BB1768DBEAAC156D42559FFCF86136ADC1EBBCBE552E7FFAB2AB1005F595FFA604F5FF301AAAA3CD0E65A124B16131C14605A8F3A2B12BD11BC535E0D20D79F6691E96D031A67C44D630DC125099E455F3E43580B1AD6F6E307D70BA2695E6F1FF0024E546C8636D46E028C110D989942A9F2F1BF8F668444D571845D0B13C0EEE5FBF1F4A7B898F06DBE19BC2E938DE3D0738ADC7BA33E0612B16D0292D0530937E3178537D2316800C45CFF990DF74ADD8822B0D953A75A6B5F1D37473FD905A296A821C0F554B59106DDF9BB2E486A7EA2EDBBFBBEC058E5F9F300C53052319BBC6E56A8B494B14AA3389965787383D8F2759C4543F491F1AA222DDD8C29217BBF7A2EF0887960F4645FE0D6499E5F5432594AA024610FA5605A3720E230B4362A50FB6BF2A583FBFABFD2F7FA9F78DC40B0E3F6805FEEC9A3223A0C1EF1A2C00F210BDB50E666E4020EC7D68A149319F2D1023C0B376DFBE31C6080C0919D141BA92FED41782BBC8F10C24894B1D3AAF1DEC2FD5559FA65F5D90864EFB2A7F9BBE2255C5B953A126D7CC44B4F4CAA8CC1772C803AE97B3A84C5B270AE0D731733F943AFFA2D05E71AA0F0C5804DF6E12B0AA3675E4407FF06F03D0FCDBDF5CC5BFBA094B689A5316DEC1B8E1935CC72AD86E3B215769C925477E23FD752A6C26CD8DF6B5576FD03642D8EA5DD52AE5EE7B8EAAB6C6BAA78779F01ADB43D49D798DE27023DD2E10253C80E94701E082F834F9D3B409CDDE5DE4AA9606C2E49B864A20E5CCD494208CC8DDB929EA4551747812E4CD44E2EB5D921A9001E4F946A9EFAD9523F1300FA42B55ADDB97CB24140B81704838767893F439629BF6C52BA591836E4EBE1BFC9E487F7CD73C11B042C261DA67D17E23B601F4105AC38F980935CAA98747101C5C4D8942260455720FCA1A1096B79334D609FA3B6F46B98823959DD543059D08B393035D870E05579DBCB80D83EA46A525FB136EB3C2511E0737861263A440B1C7E0C9A4D10A8E47BB35D2B34CDEF01F0F24515318414FF9553D2A65D5E5FAA8836165A04F5DE34D7986F99836B39174AD83608854ED757085E7EADB8D70F437B2B6D8AAA85AD18F2D0AC6B87E94FF56AB418710B84AD0BA72B6F2FF6470BA20132FD4BDA067AE716EC0BDF13A7D3E1EE90507EEFB7F03A35117AD2CBD1E7FE72BF30911A8F35C9431FFBC2AAC122C07F77BA2F674C27444729F79F6357A2B63560CD03CDD48CDD90CC4820EEE697794DDBFC95A95D2C0E7902AE6EDB9420B681A518A1C2DB694C40BF3331607721A696DD16A0D5167697733D0AADE2190E7F87696B08E21DB35BB29CD8CD3AF2F3E2D9107292579B3A646168A3C61A46CA0FCA7B276CEA1AE411653A80CFF59EE77138E6C1891F59B4D76864066A8058C383A945CB1F347E0BC4542014F16B0D3A0157161A686EEE70C3D605EEE4C7F7937F2D9354C1DE4795DCEBE7C5D5F49B25E8EBC210548451B97D6857DD5025AF3649C8F52123B6E6CC47B4075BCAB0B48EA8FA760E3ACFED59DCA182D73D2F9CA631DFEB1A83D2AF6C6E62AD2200F6662207E22BF755DE72D0BF4A1767B3D5CF5E7C2983B3CB3C5F23F5256AC5C896E7441CAB3711790EE9917719D153C10D20300C6F510726AB1A398DD3D1B4F81FD90DA8C28B60E381CD7AF990C1F7388C0022BD53ACA85C7A03DF915D14815406061E99C2E5DFBF7F1E75BF633B85955E7B5E31CA320C13977F0571045529CB3F0DD19C98E50391C8004580F4838FADCA61F45DA69A39B5D079161A4B1F1E9AB27CE4B0F2DFE7763D5824E1BDFE938DA919C1EDB23A66563B84890FA4DE4A811ADF3C86E5898A5C85564BBDF476ACDDC6209132E2945DF6DD2C0E1A191FA7B529196D3989AD3EACDD3574F6F203E53EC7466BD350DB072FA2A1ABFEC7C20A811493A94496DD531113D67EF5DA0FA45AE121E3BF1F22DCB62FAF056CA407A04B8EE3908FE6D658FBD8D49B7F3BEB50DBB8052497CA682931DE658CF712905629690F9AEC3DC89A069FB1D2F1860720B6B8FF3F2534873760402A04B7D2980737F682309F7D0AF637F5B3BFEEFF87C337D3354AC062FCCC7E96A70AD434B689A71998EC7397AEA5F6C38DC97F83C5A66579F3F49FB02885B2F15F570DA91F7139D4461DD7

Files activity

Executable files
0
Suspicious files
277
Text files
203
Unknown types
7

Dropped files

PID
Process
Filename
Type
3776
rs.exe
C:\Users\Public\Videos\Sample Videos\Wildlife.wmv
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\idb\3312185054sbndi_pspte.files\journals\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\Public\Videos\Sample Videos\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\Public\Recorded TV\Sample Media\win7_scenic-demoshort_raw.wtv
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\Public\Recorded TV\Sample Media\win7_scenic-demoshort_raw.wtv.KRAB
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\Public\Recorded TV\Sample Media\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\Public\Pictures\Sample Pictures\Tulips.jpg.KRAB
binary
MD5: fa9f27bb388dcd70d8ee5b89c99a0285
SHA256: a9e80e3678570ecbf9b88f169027d57fef6a1b565e13403af3d24e487f2fe325
3776
rs.exe
C:\Users\Public\Recorded TV\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\Public\Pictures\Sample Pictures\Tulips.jpg
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\Public\Pictures\Sample Pictures\Penguins.jpg.KRAB
binary
MD5: 9ac28c3080629f35762a27981c885c8d
SHA256: ff9b5dc124ae6312be5a6315faf6b6341a420cb14c83fdc43e9c253a1593f166
3776
rs.exe
C:\Users\Public\Pictures\Sample Pictures\Penguins.jpg
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\Public\Pictures\Sample Pictures\Lighthouse.jpg.KRAB
binary
MD5: ef38c40ff2b08396aeb0c1359dfff938
SHA256: afaa2a157dce8d255651e48e0317d6d8b4f740a3830ee8d30151b0ef5c1d6c4b
3776
rs.exe
C:\Users\Public\Pictures\Sample Pictures\Lighthouse.jpg
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\Public\Pictures\Sample Pictures\Koala.jpg.KRAB
binary
MD5: 83db43536e188f13e9e84ba394184b42
SHA256: 6d32b62e681695a3c5edcd9d6ab9fafb7ac9443752a1e43820a40d3ea2539658
3776
rs.exe
C:\Users\Public\Pictures\Sample Pictures\Koala.jpg
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\Public\Pictures\Sample Pictures\Jellyfish.jpg.KRAB
binary
MD5: fd59b7d54d76d2e9b202066f9775acb3
SHA256: 83fa5ee4efcddbbda4aeb7829ea784c0d733dc6dff160b71c74a0dd6746eca34
3776
rs.exe
C:\Users\Public\Pictures\Sample Pictures\Jellyfish.jpg
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\Public\Pictures\Sample Pictures\Hydrangeas.jpg.KRAB
binary
MD5: c532640b444db939283ab1a7d3f7b632
SHA256: 57ab9cd8dd7d0f7af16dba2b3dcd47fa66842798c8357aa680a904d44b0a1e68
3776
rs.exe
C:\Users\Public\Pictures\Sample Pictures\Hydrangeas.jpg
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\Public\Pictures\Sample Pictures\Desert.jpg.KRAB
binary
MD5: 8128cea53b58b2e599b34284d6df6f62
SHA256: ac192e900200ebf98f7a9fe51303f1ea23df441d0f2aa60cd447972129c0bf75
3776
rs.exe
C:\Users\Public\Pictures\Sample Pictures\Desert.jpg
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\Public\Pictures\Sample Pictures\Chrysanthemum.jpg.KRAB
binary
MD5: 07d4484a635b0f0ae4e21e431788903c
SHA256: 84a5823377aaa27c71da2bac0e3e9f298752cb63494843bcea54b4bcbc79581e
3776
rs.exe
C:\Users\Public\Pictures\Sample Pictures\Chrysanthemum.jpg
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\Public\Pictures\Sample Pictures\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\Public\Music\Sample Music\Sleep Away.mp3.KRAB
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\Public\Music\Sample Music\Sleep Away.mp3
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\Public\Music\Sample Music\Maid with the Flaxen Hair.mp3.KRAB
binary
MD5: f11ee7e889742ab43182b40a79588813
SHA256: a3c6ff10b1f2cb68c9fa62d5d8084d4280ee2e23373548e695751fada10744ea
3776
rs.exe
C:\Users\Public\Music\Sample Music\Maid with the Flaxen Hair.mp3
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\Public\Music\Sample Music\Kalimba.mp3
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\Public\Music\Sample Music\Kalimba.mp3.KRAB
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\Public\Music\Sample Music\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\Public\Libraries\RecordedTV.library-ms.KRAB
binary
MD5: 79ace1cffd080f4d58477e37fe4dee81
SHA256: f5da7e9475580fd783565e1694f6c926dae556b7fc6e3c6b2483271f220785ab
3776
rs.exe
C:\Users\Public\Libraries\RecordedTV.library-ms
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\Public\Pictures\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\Public\Videos\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\Public\Libraries\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\Public\Downloads\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\Public\Favorites\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\Public\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\Public\Documents\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\Public\Music\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\SendTo\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\Searches\Microsoft Outlook.searchconnector-ms.KRAB
binary
MD5: 638fabdc8229cd9bc6975493de6b276d
SHA256: 80d1029ce15b320c45149bc6876bae036da06016c2ec5598769fd2ec32752f8e
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Templates\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\Searches\Microsoft Outlook.searchconnector-ms
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\Searches\Microsoft OneNote.searchconnector-ms.KRAB
binary
MD5: ede52bd06cd44b95995ad8e52cf633bf
SHA256: fdc759dba55f611527775c57d89a2884f005f131612107925e0924761f870730
3776
rs.exe
C:\Users\admin\Searches\Microsoft OneNote.searchconnector-ms
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Printer Shortcuts\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\Searches\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\Pictures\registeredalmost.png.KRAB
binary
MD5: 7767bbea7089ed656dab0440e6a834c6
SHA256: c04885eb93c9aa23877df942cb2901596573d0b2a3bcbba12a05bf23505f8a17
3776
rs.exe
C:\Users\admin\Saved Games\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\Pictures\registeredalmost.png
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\Pictures\howdegree.png.KRAB
binary
MD5: 6243ae4de2880c44fef428ffcd719381
SHA256: 9b1c1f05e3f4c3c3b04e329e7d9e90305e60bd0694e40c436205ca75e10bcf97
3776
rs.exe
C:\Users\admin\Pictures\howdegree.png
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\Pictures\environmentalfilter.jpg.KRAB
yz1
MD5: 118ac4d7cb3109663b0679557b960de7
SHA256: 127f8300e7c8f6f30fdeb20808f0d53f8c0e13858c20f83e3527a7a6f22771c9
3776
rs.exe
C:\Users\admin\Pictures\environmentalfilter.jpg
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\Pictures\countyresource.jpg.KRAB
binary
MD5: 0310eed2a7835bae8ffdd2b3c28a1eca
SHA256: a4633afcd081a4159bec200731fd5d4cb3e7691282ed17f43ee568b31f5d5bfb
3776
rs.exe
C:\Users\admin\Pictures\countyresource.jpg
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\Pictures\allowlead.png.KRAB
binary
MD5: 02ebb38fc1fb4f42af7d919ee47f0182
SHA256: e92a8e9bd854807f94511b3315043fe9746d82e2a6a5cafd1bc10e68a8a40ec4
3776
rs.exe
C:\Users\admin\Pictures\allowlead.png
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\Pictures\agencysafety.jpg.KRAB
binary
MD5: b419d314343c43528c1162c8c0a299b4
SHA256: a98a7df427e20787b15d9f26418006175cc2d0e5f5b68e05d3e7b9dd24050f48
3776
rs.exe
C:\Users\admin\Pictures\agencysafety.jpg
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\ntuser.ini.KRAB
binary
MD5: a5fc436cb63e3a3ba38de32f72c51a4c
SHA256: d1782255abbde47ea0aa8f479921d0028913cd2c5df330490db6eb6f20d6956c
3776
rs.exe
C:\Users\admin\ntuser.ini
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Network Shortcuts\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\Links\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\Favorites\Windows Live\Windows Live Spaces.url.KRAB
binary
MD5: 6def39f0b596f78f6f31ea28669fd549
SHA256: 64e203c57d662967861190aa86fbdb993eaf5235754e2222c623861a971fbe5f
3776
rs.exe
C:\Users\admin\Favorites\Windows Live\Windows Live Spaces.url
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\Favorites\Windows Live\Windows Live Mail.url.KRAB
binary
MD5: c91357181f7bcffe43373b5a3b9286f7
SHA256: 7e1fc3b704a4b9370e95e8bc29c5328836b0259009ca4a0e85b939ac77be034f
3776
rs.exe
C:\Users\admin\Favorites\Windows Live\Windows Live Mail.url
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\Favorites\Windows Live\Windows Live Gallery.url.KRAB
binary
MD5: 9fb8e89a182e0493f965a0e055d8e5e8
SHA256: db9f16ac767322b127cd632dbaf8d952e1273b4f829dd526903f0f0643ce5a64
3776
rs.exe
C:\Users\admin\Favorites\Windows Live\Windows Live Gallery.url
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\Favorites\Windows Live\Get Windows Live.url.KRAB
binary
MD5: 7bb13eeaa7bac86842eff1be26af52ae
SHA256: 5438a9135b2a3ad09ffb0e279e27e409d1b1fec46658e27d4f7c046902213ee0
3776
rs.exe
C:\Users\admin\Favorites\Windows Live\Get Windows Live.url
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\Favorites\Windows Live\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\Favorites\MSN Websites\MSNBC News.url.KRAB
binary
MD5: a9b8c9306fd3b00e3e48b5b9f852e4f7
SHA256: 08328f580a3577b8945ce99a8b82f40ca7d74ae5240ec01d41f3b6ffdd03a946
3776
rs.exe
C:\Users\admin\Favorites\MSN Websites\MSNBC News.url
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\Favorites\MSN Websites\MSN.url.KRAB
binary
MD5: 7d96af697fe42ba40ee5c8947e8e49f7
SHA256: f78aa0cba966f43685f9203b6ba543a2de810870dd13ce5e8ab2739622cccbd9
3776
rs.exe
C:\Users\admin\Favorites\MSN Websites\MSN.url
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\Favorites\MSN Websites\MSN Sports.url.KRAB
binary
MD5: c914018090e234d32d5334e3901783d8
SHA256: 4f3ff05cd4dd2443984a69201b16d8c3f1c6e028c0aae8d3f5db129a72c2d106
3776
rs.exe
C:\Users\admin\Favorites\MSN Websites\MSN Sports.url
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\Favorites\MSN Websites\MSN Money.url.KRAB
binary
MD5: 65c5ac30b3694bfb9b7c38776c6f0ef4
SHA256: 8ac9e0e21a65d06ea499e3906b0ea9b8b24a5f3ca5d76f609f7fd55f12267661
3776
rs.exe
C:\Users\admin\Favorites\MSN Websites\MSN Money.url
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\Favorites\MSN Websites\MSN Entertainment.url.KRAB
binary
MD5: c69582c13efe66e2aaefa264bf208121
SHA256: f8df63d31d8c9ae7d7853e9d1c8f31295c9eef1f674ed74ca2b67bfea2e717c7
3776
rs.exe
C:\Users\admin\Favorites\MSN Websites\MSN Entertainment.url
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\Favorites\MSN Websites\MSN Autos.url.KRAB
binary
MD5: aba874db577b33b8d1e6b5756f4cb689
SHA256: fc4f9d92ff50fde7d849fd8a56966a495cb2f0387b46f05f75355491f5aaf56a
3776
rs.exe
C:\Users\admin\Favorites\MSN Websites\MSN Autos.url
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\Favorites\MSN Websites\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\Favorites\Microsoft Websites\Microsoft Store.url.KRAB
binary
MD5: 44d6601e123839f2eaf6599f3a318754
SHA256: 50f58b3fd2e88ade8fe62b253e56c0d41e4602df998473d765f808ab7e2b2a21
3776
rs.exe
C:\Users\admin\Favorites\Microsoft Websites\Microsoft Store.url
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\Favorites\Microsoft Websites\Microsoft At Work.url.KRAB
binary
MD5: 152834d82f69b9798b13bb6d26a7de53
SHA256: 2cd6e453ed43e6cfb59ae6e4ff420a8aaefa70b632c2046c12eb39350dc4cb05
3776
rs.exe
C:\Users\admin\Favorites\Microsoft Websites\Microsoft At Work.url
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\Favorites\Microsoft Websites\Microsoft At Home.url.KRAB
binary
MD5: 7c3168778a222dc5af028e4acabda4df
SHA256: 58b902f57b2c3a2e4e38be61f423b214e17061ab5265e15c78d987c9f353b6ba
3776
rs.exe
C:\Users\admin\Favorites\Microsoft Websites\Microsoft At Home.url
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\Favorites\Microsoft Websites\IE site on Microsoft.com.url.KRAB
binary
MD5: 92ac5e2e4c0a4bf3a5883c88f75ed2f4
SHA256: 7561094881744ed994779c2005a358386396d677d92a238426cd54bd7bf98968
3776
rs.exe
C:\Users\admin\Favorites\Microsoft Websites\IE site on Microsoft.com.url
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\Favorites\Microsoft Websites\IE Add-on site.url.KRAB
binary
MD5: 1159a96c09424f7165c309106cf8eb2f
SHA256: 1d422d2d2269683d1c748ac72768688c5acfe35790f0a89628629d2f03237eb6
3776
rs.exe
C:\Users\admin\Favorites\Microsoft Websites\IE Add-on site.url
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\Favorites\Links for United States\USA.gov.url.KRAB
binary
MD5: 227ef67fb7f5df2700eaccce3c4213ae
SHA256: ed543a26cd3634b30cc881ffaa1361082ba6077c1dde109b285394c332177ad6
3776
rs.exe
C:\Users\admin\Favorites\Microsoft Websites\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\Favorites\Links for United States\USA.gov.url
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\Favorites\Links for United States\GobiernoUSA.gov.url.KRAB
binary
MD5: 5c74fffa1a33e48863f4b45a132f1bf1
SHA256: c38352f249844f2db46214d5ecd7fd4a31d8116c9b6320135a80efeefc5428b7
3776
rs.exe
C:\Users\admin\Favorites\Links for United States\GobiernoUSA.gov.url
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\Favorites\Links for United States\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\Favorites\Links\Web Slice Gallery.url.KRAB
binary
MD5: c1d27ac05d02d1dc1176b0a6f6bfa1c7
SHA256: 31e25bb2e0f1792be156e97ce05eff8d1ff7a2b63f49c03f99c3514e6b008dd6
3776
rs.exe
C:\Users\admin\Favorites\Links\Suggested Sites.url.KRAB
binary
MD5: db5b7dfc20cecb3a80f037cd7ce4eacc
SHA256: ac62e3f25af7ce98b256617208ba0f03593b127863fb32590d07f080bd1aad4d
3776
rs.exe
C:\Users\admin\Favorites\Links\Web Slice Gallery.url
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\Favorites\Links\Suggested Sites.url
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\Favorites\Links\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\Downloads\rapevehicle.png.KRAB
binary
MD5: e9b0227e88449a719653bfc97f63ac82
SHA256: 206ef1e25a260da916c5f52bf11ff233a4916d3a16af904ce2cafe5b7bb1bd01
3776
rs.exe
C:\Users\admin\Favorites\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\Downloads\rapevehicle.png
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\Downloads\growthmain.jpg.KRAB
binary
MD5: 12f8f467ca5f8ee942a7624b25aae387
SHA256: c78140cbfb92a85d9bc2f72286e8624b950035129e0b3b2f0e6c5e8863c94f34
3776
rs.exe
C:\Users\admin\Downloads\growthmain.jpg
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\Downloads\feelautomotive.jpg.KRAB
binary
MD5: 1bfada7551343e89acd180ecfe9e8071
SHA256: 7a1d6ac967a7caa271ad12b591b8929f40a37f92f1146e61934125d1a666cf3d
3776
rs.exe
C:\Users\admin\Downloads\feelautomotive.jpg
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\Documents\trialcause.rtf.KRAB
binary
MD5: 0c356a20d210912ec34049bdfef88a8e
SHA256: 025b08a32e824ef735aedb13b650113dff0e5ee1dea6ea68d2335f5562272ee5
3776
rs.exe
C:\Users\admin\Downloads\alindividual.png.KRAB
binary
MD5: ced1ea075e7e61448ce389c00c2426e6
SHA256: a96ab29118ea0177f98ee9d77bad2449e1f43acdd287f5dc74fd5af2c990c3bf
3776
rs.exe
C:\Users\admin\Downloads\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\Documents\workgalleries.rtf.KRAB
binary
MD5: b5e24f6eba5ad839d394e4555ee4c5fa
SHA256: 8b6c034887fb9765737b86f69a787fed80688c0b3149422361a4a0ae79ecfa8e
3776
rs.exe
C:\Users\admin\Documents\workgalleries.rtf
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\Downloads\alindividual.png
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\Documents\trialcause.rtf
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\Documents\standardsso.rtf.KRAB
binary
MD5: 77ebfa26ae60ba1e9355e6968999d22d
SHA256: f9eac88ec57fee913722430953b2dfa02d1d168d753e51492537e4104effcb0a
3776
rs.exe
C:\Users\admin\Documents\standardsso.rtf
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\Documents\Outlook Files\Outlook.pst.KRAB
binary
MD5: ab304c38c0f88abe20b59f2568a053bb
SHA256: cbc6d788de7764bfcc8ec4ddcd937b3e6fc433ec6ddca02239dc2336857f0335
3776
rs.exe
C:\Users\admin\Documents\Outlook Files\Outlook Data File - test.pst.KRAB
binary
MD5: 2f6ba4623f85e9058455b19292e5ec0d
SHA256: 9eb9ebc712befa3b173cab99b51d08b225dab7a0caaefd31e6eb6268152d5fe4
3776
rs.exe
C:\Users\admin\Documents\Outlook Files\Outlook Data File - test.pst
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\Documents\Outlook Files\Outlook.pst
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\Documents\Outlook Files\Outlook Data File - NoMail.pst.KRAB
binary
MD5: fde7d62756873b54532a92e2215038bc
SHA256: 390b79e01ff31e92faf8600e4f5f8408abcbf6fc04990a75364b2fa053917474
3776
rs.exe
C:\Users\admin\Documents\Outlook Files\Outlook Data File - NoMail.pst
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\Documents\Outlook Files\[email protected]
binary
MD5: ff988c44b4d1b719350465827da5790f
SHA256: 5aa10afe1a9f4eb334023f81c8ee0580af1250da7ddec3bd21c597bc84344dfc
3776
rs.exe
C:\Users\admin\Documents\Outlook Files\[email protected]
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\Documents\Outlook Files\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\Documents\OneNote Notebooks\Personal\Unfiled Notes.one.KRAB
binary
MD5: 690152d17f0fae6d0c32214ab6866922
SHA256: 2f6884b41bc26cb6142745cf8385e53692ffb151f7208606c8c0c29d4b500313
3776
rs.exe
C:\Users\admin\Documents\OneNote Notebooks\Personal\Unfiled Notes.one
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\Documents\OneNote Notebooks\Personal\Open Notebook.onetoc2.KRAB
binary
MD5: c1fa79143f21db48057bff14082d05f4
SHA256: 5f20a293917003a31dc3a016fdeec68a0c0459a5d733f3f68990f770029d2713
3776
rs.exe
C:\Users\admin\Documents\OneNote Notebooks\Personal\Open Notebook.onetoc2
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\Documents\OneNote Notebooks\Personal\General.one.KRAB
binary
MD5: 7a43dc01c819dac890cca2f9fa48958f
SHA256: 0c9b0a0ed1e7796152280f7cb60ae9d9db0d213c1365176e9f569f96fa85db5d
3776
rs.exe
C:\Users\admin\Documents\OneNote Notebooks\Personal\General.one
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\Documents\OneNote Notebooks\Personal\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\Documents\OneNote Notebooks\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\Documents\notheard.rtf.KRAB
binary
MD5: e5dcba6eaef3ffc6fc5ca74c7703d8cf
SHA256: 6cb939d1b674f216c4487bb5e4323a415c17f9c6bf673e6a932e2937f3dd23c1
3776
rs.exe
C:\Users\admin\Documents\notheard.rtf
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\Videos\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\Music\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\Pictures\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\Documents\cnetannouncements.rtf.KRAB
binary
MD5: 67458ef5ba6f679481c013b3f31caa33
SHA256: 3893cd2a9e9ccd5f6ca1d1e01b15e79ce51c011bbd4d092ee0a12910634e7a24
3776
rs.exe
C:\Users\admin\Documents\cnetannouncements.rtf
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\Documents\clickrent.rtf.KRAB
binary
MD5: f93a621c90560129caefe94a076fb994
SHA256: 9e084f99d4f935d216a33d0e3de27f7e69904761ed10fbd8de1309aed0c8b278
3776
rs.exe
C:\Users\admin\Documents\clickrent.rtf
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\Documents\audiopressure.rtf.KRAB
binary
MD5: 302f80cb979cf1264291adddac81d805
SHA256: 3d7e9bba0a87974e46d7d4a6d505887dac1866b066b8caff77ce9d4143676c9b
3776
rs.exe
C:\Users\admin\Documents\audiopressure.rtf
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\Documents\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\Desktop\whatkitchen.jpg.KRAB
binary
MD5: edee2f7e59430aaf65459aec60fbe669
SHA256: 22b5a95d5faf78086ee15758f8d4824301a513caeba52498910324ba5f4e1514
3776
rs.exe
C:\Users\admin\Desktop\whatkitchen.jpg
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\Desktop\tryposted.jpg.KRAB
binary
MD5: ee401f9e2444b8f7f2db62a8579f4eb7
SHA256: 3daacb738222a8f0de8b3f80cb4eaf653bc2a0520845d9b7c4f82053ee9613d0
3776
rs.exe
C:\Users\admin\Desktop\tryposted.jpg
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\Desktop\topicmicrosoft.jpg.KRAB
binary
MD5: 6d7bacaacc8fa8fe9179e3275215ccee
SHA256: bb3b803ecd08e304be1fa1806a41d6a8ea6aaa6523c99e5e22c704b233e4c154
3776
rs.exe
C:\Users\admin\Desktop\stateclient.rtf.KRAB
binary
MD5: 9f741c8724b08d898fa6e9e07ba936a1
SHA256: 8cf93efd38961779e196b9b6d0f0ca2efa0dd5d057d4e3111940ee7cc693e1e5
3776
rs.exe
C:\Users\admin\Desktop\topicmicrosoft.jpg
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\Desktop\stateclient.rtf
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\Desktop\satmust.rtf.KRAB
binary
MD5: fc26ba6405a75b6d62de75a5807c3f16
SHA256: c7c6e0841c2352a2809f2e25f589b9463643e57a553b31ee6c023c4b378513ca
3776
rs.exe
C:\Users\admin\Desktop\satmust.rtf
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\Desktop\quitebus.png.KRAB
binary
MD5: e84bde9621ddc86266b2dd1f1ddf4b2f
SHA256: 62fc2406df03b5c21068e74d2e4d3027156878899c3f68c9ed4e7280daa7f4d9
3776
rs.exe
C:\Users\admin\Desktop\quitebus.png
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\Desktop\popularwhite.png.KRAB
binary
MD5: e71c28cc9c6c448734e4f0fd2db4b993
SHA256: 2be06691fc75b660a7c050af6ce40ec82244684d4714cea5b9b9f2f1cc276aa6
3776
rs.exe
C:\Users\admin\Desktop\popularwhite.png
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\Desktop\multiaccess.rtf.KRAB
binary
MD5: c85abf507f91c99bc19589e6659ab71c
SHA256: 8ac1772fbfda1e98577479fcc99d09211b0f4a8ab5eb801e8d2f49a3365d6e18
3776
rs.exe
C:\Users\admin\Desktop\multiaccess.rtf
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\Desktop\monththank.rtf.KRAB
binary
MD5: a737ab0b8ffb17967a47b8e36143c891
SHA256: fac83fcc38f54297de60dcf1649eae9144bb6c6bd90144ac471b50c4538f3dcb
3776
rs.exe
C:\Users\admin\Desktop\monththank.rtf
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\Desktop\holdoverview.rtf.KRAB
binary
MD5: f6d860e903aca3577f1bb3ebcd92411a
SHA256: 519adecbe73995d783c5260eb9f4df1f407bce4207f70693452f2be2b34213ad
3776
rs.exe
C:\Users\admin\Desktop\holdoverview.rtf
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\Desktop\asartists.rtf.KRAB
binary
MD5: 8d3a2286619bbe009b53d8dde30e795c
SHA256: 89a787a80846dc5770230844fd89a5cd9601bf98c55ff08e2d5617d5469f6f8c
3776
rs.exe
C:\Users\admin\Desktop\asartists.rtf
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\Contacts\admin.contact.KRAB
binary
MD5: f4f71873987011330aeb1c1ef484fe3c
SHA256: e6fc9606b38d9727b07294f6e2d8d7572807411ba482a30c54b2cf3b13c806f0
3776
rs.exe
C:\Users\admin\Desktop\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\Contacts\admin.contact
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\Contacts\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Sun\Java\Deployment\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Skype\SkypeRT\ul.conf.KRAB
binary
MD5: 1408ea2634ced7d577c332d5d878865d
SHA256: 5b6812325706997fb0c6b3c757636bebe971cbc2eccb9708533786c05dccc72a
3776
rs.exe
C:\Users\admin\AppData\Roaming\Sun\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Sun\Java\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\WinRAR\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\WinRAR\version.dat.KRAB
binary
MD5: cc24ce1fea00a090f5e4a8cb71541805
SHA256: 0c8275e1fcbde4a8589666a1e529110bd1b3ad9d13f5c5512453698cc105a93d
3776
rs.exe
C:\Users\admin\AppData\Roaming\Skype\SkypeRT\ul.conf
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\WinRAR\version.dat
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Skype\SkypeRT\skypert.conf.KRAB
binary
MD5: 2b07a58ca98efe17bc2e99d1b0e61e65
SHA256: 489c05c121a5ac205df6b00b6075f8a3fc57b2ae3b992d1a508c7bc4263a962b
3776
rs.exe
C:\Users\admin\AppData\Roaming\Skype\SkypeRT\skypert.conf
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Skype\SkypeRT\ecs.conf.KRAB
binary
MD5: f5947292f8e15ff3b985f3a19d385701
SHA256: 5096011e447a51f000a2874d1e78b3110f85de49caa76d1224ebb5d129731477
3776
rs.exe
C:\Users\admin\AppData\Roaming\Skype\shared_httpfe\queue.db.KRAB
binary
MD5: 896003acefc526d52d703c027af572f3
SHA256: bfca062fb7a1e961f6d710963154f76e0dec223d62503a86e9fbffdf9cecd9e8
3776
rs.exe
C:\Users\admin\AppData\Roaming\Skype\SkypeRT\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Skype\SkypeRT\ecs.conf
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Skype\shared_httpfe\queue.db
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Skype\shared_dynco\dc.db-journal.KRAB
binary
MD5: 93daa12995c16bb18c3d1d14ba88bbb1
SHA256: 5120fe459cb3acb8b42b4a3b49718fe1eecde195fa2273a6b592dbeacae05404
3776
rs.exe
C:\Users\admin\AppData\Roaming\Skype\shared_httpfe\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Skype\shared_dynco\dc.db-journal
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Skype\shared_dynco\dc.db.KRAB
binary
MD5: c2e3da9e1366fc18b7d16cd92f8039f6
SHA256: ee10cabaadb273c03fb2ab679bdd00a577a4a86d33a233a42a3d0a8100b72328
3776
rs.exe
C:\Users\admin\AppData\Roaming\Skype\shared_dynco\dc.db
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Skype\shared.xml.KRAB
binary
MD5: 018c8059035fdd6c06a0fd27a23b788d
SHA256: d378743aacab956b5791679641fab1d1951bdbcacce944bad212bfd21c1325f6
3776
rs.exe
C:\Users\admin\AppData\Roaming\Skype\shared_dynco\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Skype\shared.xml
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Skype\logs\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Skype\DataRv\offline-storage.data.KRAB
ini
MD5: c5fbe021f967cfcaeda8ae7d249ca262
SHA256: 89dc3d50aa2a278bc6a1ca20d62bd3e631904089a2fd63cc40ddecaf073696b0
3776
rs.exe
C:\Users\admin\AppData\Roaming\Skype\DataRv\offline-storage.data
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Skype\DataRv\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\webserver\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Skype\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\webserver\users.xml.KRAB
binary
MD5: 20eba5b17d6cc263f17e8b9ce158b148
SHA256: 1fc9f075501f05966a1d5030ec375f12967308ccecf267e10fc955572740d1e1
3776
rs.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\webserver\users.xml
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\wand.dat.KRAB
binary
MD5: d3a98c9f41b0bd654fe3b4d6948c5473
SHA256: 7570e28832c655d96150c0616b86bdbce9df8c03f2701d2feea0c2e51e5b1f99
3776
rs.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\wand.dat
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\vlink4.dat.KRAB
binary
MD5: e91c08c85b34571e4d6e1fd0e2e7362a
SHA256: 0eeca1d0fa743b3776a65c9be578f665ff4493a0bc31e4610d9b6476163abd67
3776
rs.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\vlink4.dat
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\typed_history.xml.KRAB
binary
MD5: c4a561c9b17b067619dbce296d6a744a
SHA256: 8f0537aaad5975dcbb50cae31382299b9fc070df815c2600d3dff17edd012a83
3776
rs.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\typed_history.xml
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\tips.ini.KRAB
binary
MD5: bc108fb3a1a7a1a7afca328cd5a5ac4a
SHA256: 777c557e685b87dc0998f80f42ff63506f6a2697d51415b55f07625627da3784
3776
rs.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\tips.ini
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\tasks.xml.KRAB
binary
MD5: 3fc1ffc973f6e5044b73e373bfa39247
SHA256: 7c510267361881e0a8151981eec97be27394a9c308161bd0c77afa35031ea48f
3776
rs.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\tasks.xml
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\toc.css.KRAB
binary
MD5: 586e9df89e2ed9abde92d9cf1b97e37c
SHA256: e250cb01de8b013e3d703fc1ed2e2c6b08303d736ec6ef99ef2ff0895c3cd820
3776
rs.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\toc.css
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\tablelayout.css.KRAB
binary
MD5: 6bcc70b2fae5f3dc5b3b8160142f7a3e
SHA256: 40a560c9df1105f3a17d15282e688ba2b2bbbbb4bb836636f272c9a5646f2525
3776
rs.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\tablelayout.css
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\structuretables.css.KRAB
binary
MD5: 0dee9862d5024783cd2b941e459ece1a
SHA256: 1516de83e7feb6473c1038cfa040beae6ccf364da62b1643d53fdc50d5259d27
3776
rs.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\structuretables.css
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\outline.css.KRAB
binary
MD5: d83323ceca3c52046feddc8b6b531832
SHA256: 8ef37473aff9558915f88baf3f5e04e28629cda634eeb8b903c64726b47bd9c5
3776
rs.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\structureblock.css.KRAB
binary
MD5: 2f3f1a48767cbc0cdef2ac8e98fc359c
SHA256: fb65002d213033084e6d45db503359c93d14c30ebc1e5b0855d70274cf7bbff6
3776
rs.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disabletables.css.KRAB
binary
MD5: 0f3c787b1274e961794b7452f3234a3f
SHA256: 7824119a4d786286097ebf4ffa8ea3d20b347fa529ce4b189ff2306748bad263
3776
rs.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\structureinline.css.KRAB
binary
MD5: 7f86979d26400a9ccd85be4eae95359f
SHA256: 265f2abeed97c4f0d732e64aa23485680b97e0cb7fb4a20bee0e42b5a921f699
3776
rs.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\structureblock.css
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\structureinline.css
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\outline.css
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disablebreaks.css.KRAB
binary
MD5: 8b0cca1e18d60bf94a4141a2d130232b
SHA256: dd2f1b2b0ce5378c5ed6918200720b0bb6cb93eafa4329ea182403acf436c7ca
3776
rs.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disablepositioning.css.KRAB
binary
MD5: eccdc5f4091d10eb6e8026741e870c07
SHA256: 149378ff74b43f8c4375a43e1383fd10a55642f7900313047e81d64148b4f177
3776
rs.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\contrastwb.css.KRAB
binary
MD5: f70f82dce609b72ddcdf008a6010c3ae
SHA256: 6fbd893cbc5b9314b34821d4fdb931334cdb255d91c855a509861f6c0253714d
3776
rs.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disablefloats.css.KRAB
binary
MD5: 9af659241bf136cf32f1098683e9249c
SHA256: 7c456ffc5d379fd83e6de0b1bee7ee6174663afadf9fce09522a29fe33f39cfc
3776
rs.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disableforms.css.KRAB
binary
MD5: fd4cd187755eb22ac12b546991b2de06
SHA256: 4f29f6a2a05d65063fedf10b834a4d6c2f40255ec2c83e1b5e458e3b672f1eb1
3776
rs.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disablepositioning.css
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\contrastwb.css
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disablefloats.css
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disableforms.css
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disablebreaks.css
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disabletables.css
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\accessibility.css.KRAB
binary
MD5: 79ae723cd5df757fc22606158168b1c7
SHA256: 4092672d14ff870ba7c13face54d612968579ef24650f566e687bcf57dd32a1d
3776
rs.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\speeddial.ini.KRAB
binary
MD5: 0da69cb1f8b8ea7a8d3443b07cbc4e78
SHA256: 69f224a73182d94a52f1e731741a191a4461080e09c7b862b277ee6d62c1302f
3776
rs.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\classid.css.KRAB
binary
MD5: 41111458e77fe80d49030d74f61f3508
SHA256: 0733f9296e2c441b18899f618d5cdf84cc91db5639f46c840d99c9d49b1db1aa
3776
rs.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\altdebugger.css.KRAB
binary
MD5: c9ee4362fb8eccd524d910ad31d81624
SHA256: 8afeef959041c0dbd1392f4bfc49a4cc56960d87fb245ef2bb73fa39e541b495
3776
rs.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\contrastbw.css.KRAB
binary
MD5: d5e07bb3d2b43941fbddc8b9cb091834
SHA256: 85fd006ddca5593e6d2fbed85904d3e94e9e180d2093b282ff4fd8a477419b1e
3776
rs.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\altdebugger.css
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\speeddial.ini
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\accessibility.css
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\contrastbw.css
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\classid.css
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opuntrust.dat.KRAB
binary
MD5: 0f69ff9baba10a4bd006c3b48321c18a
SHA256: 0d60e597a8370637f0cb92394c927ecef429c468a9fd3ed1a0f1c35f20bce299
3776
rs.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\sessions\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\optrust.dat.KRAB
binary
MD5: 9eda020ebf1e433e03863d327405e6cd
SHA256: 0f96a60e847a448762a161b48817ffb7de78e1eff43761fa8f6290014c9c3a2c
3776
rs.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opssl6.dat.KRAB
binary
MD5: 2bf4683f7c101b20ddef7a439b0b6130
SHA256: 3831d532df7b4d68578b552192ebf4ad465bd7ac0b1037aad5d79244a60167eb
3776
rs.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opthumb.dat.KRAB
binary
MD5: 03883a917abe67f1b000451981afd22d
SHA256: 8cf818f883f097ae297567ec3677bda3d2808546839246cd076555c3f5239360
3776
rs.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\oprand.dat.KRAB
binary
MD5: 4a6f031fd3bacfa1e3c078cbca32e139
SHA256: 0e6a1c2ef22c617b867a033e3abf5dc39f80e9e3bc61caf6f84c5f0e72d380bd
3776
rs.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\sessions\autosave.win.bak.KRAB
binary
MD5: d90e8ce78f3bdbc372899a418bf59cac
SHA256: 89be1c220d70935abbbb383d968ded3d61caeb04fadbf7293ff4035ea84eab11
3776
rs.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\sessions\autosave.win.KRAB
binary
MD5: c27725e11dc008fcfb65861905d01d01
SHA256: d5818f8aa35d8b7f8b5f7839f57a9ecfa0d849e4ac76152fe0b0ed24d448bad2
3776
rs.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opicacrt6.dat.KRAB
binary
MD5: 7e600e502bf0bac27108825b25947978
SHA256: f845dacba812346db4f133b101ec9ea8fc4e50afa7442208ac7b78086813d770
3776
rs.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opicacrt6.dat
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\sessions\autosave.win.bak
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opssl6.dat
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\optrust.dat
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opthumb.dat
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\oprand.dat
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\sessions\autosave.win
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opuntrust.dat
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\handlers.ini.KRAB
binary
MD5: 06401d114f082bf86adf2b0ecfa2526f
SHA256: b22d608677a6546c60af0f848b7daebd198dfc8efef9bf61eab2b220c744b1be
3776
rs.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opcacrt6.dat.KRAB
binary
MD5: c52220cc43df2a6ef7e8db867e7e0262
SHA256: 1542382d664da5487eeaddf3d464cf4fadf83576cbd96484acb2018df97c3bc4
3776
rs.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\operaprefs.ini.KRAB
binary
MD5: 237e8b8ec3c2e7cafc0b25d966fc8305
SHA256: 75288f41827825171ebe5f20aff0baddf09974cad5071155404e73e540f31f0d
3776
rs.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opcert6.dat.KRAB
binary
MD5: ffefe627fafd5c2a353b44f7d3027e15
SHA256: 436edeceb2bea2d2049072bae9561725700315be1cdfeb559b5842516bf0732f
3776
rs.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opcacrt6.dat
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\handlers.ini
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opcert6.dat
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\operaprefs.ini
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Zenburn.xml.KRAB
binary
MD5: c8aaf0165b65f580b14a86221ce6f6b7
SHA256: 5cbd89bc7b6c4cfe02e2a94713a712cf4aeefb82dbd913717cc75f846af5d45b
3776
rs.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\download.dat.KRAB
binary
MD5: 2c2a064563fceec6fb12912d962d995a
SHA256: bc72b934c20e864a36b236e351f85b28ab6bf9e630925a163446c041da434afb
3776
rs.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\bookmarks.adr.KRAB
binary
MD5: d34697c2e4d5fde9b4b30b41e1ade68a
SHA256: e0fad1293d4c176137f970e58d3296b74fd9e1baf3bd3f28ddfd8f90a1d06393
3776
rs.exe
C:\Users\admin\AppData\Roaming\Opera\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\vim Dark Blue.xml.KRAB
binary
MD5: f1d6a4cb2811b6f3ef0ebfe5283ec9f7
SHA256: 7a3e626e524cef256bce26f0737f7bc2fdaa87ee6ce19d8834e02a791752dc17
3776
rs.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\cookies4.dat.KRAB
binary
MD5: ab7a7da1b7724beb6cff7ea2e3e1638f
SHA256: 6f5bea95a39d8d19fe0530103304d66f31d4e2794874f94efc4a9f32c0c79df7
3776
rs.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\global_history.dat.KRAB
binary
MD5: adf0e7fa3f75e357de80544c50b53151
SHA256: 5e4dd3748fd90264d7553340cd22277841fd9b70af9226b6f8f0364cf6225716
3776
rs.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\bookmarks.adr
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\cookies4.dat
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\global_history.dat
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\download.dat
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Zenburn.xml
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Solarized.xml.KRAB
binary
MD5: dd476bf34f347b93c7f4debe15b2b70f
SHA256: ba494ff26efea5f2b1f873d4c128b54b9605c8fd04725c4ff089943c3127afed
3776
rs.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Solarized-light.xml.KRAB
binary
MD5: e628f64f624fde35b70de9a598ee2695
SHA256: 1311d0f4525d765860307f8d24e8d80237a1d158d4e9334869a21bf57e57359e
3776
rs.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Twilight.xml.KRAB
binary
MD5: a32b1fbd093d50c9ec5ce18ed6dd26c0
SHA256: f185c849d31b2012a090df5ae082a283f623b8e233692579ce94cb8e802b1232
3776
rs.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Ruby Blue.xml.KRAB
binary
MD5: b191331ce03352281248c22706808c8a
SHA256: b53f0b1d6a81c569d5809938d045e34998032fcf7959c697c00d247240d0239c
3776
rs.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Vibrant Ink.xml.KRAB
binary
MD5: c9f71e1509d481ceafb77487101e5354
SHA256: f09307d8bd467d9b499dca0e35e45945b250a6f9e1eef55c6fb108b2f807afdc
3776
rs.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Solarized.xml
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Vibrant Ink.xml
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Solarized-light.xml
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\vim Dark Blue.xml
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Twilight.xml
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Ruby Blue.xml
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Plastic Code Wrap.xml.KRAB
binary
MD5: beac0d4722ccb7abce2b73e57f44afe5
SHA256: 527c689e493b28b0c9d34ff3ea1a275a68a8106c5559bb468206b316e312a41e
3776
rs.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\MossyLawn.xml.KRAB
binary
MD5: 0d36c99118ec3621dfa3d892b3a85396
SHA256: b76d3cd88ca113b2f68bd10de9537631d22622417d3f223bf6eb6fcd786f56bc
3776
rs.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Monokai.xml.KRAB
binary
MD5: 8dcf3a0f6dd9e5e30ea17aabcd5704dd
SHA256: e5a9ab9334f3622fe37043668b3aa469f04fdb5773670ddaf4723ef4ba498cca
3776
rs.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Obsidian.xml.KRAB
binary
MD5: 4d562e5bb59f6b333a92fdfc9f04b030
SHA256: 15e9641b3d15d4196da7100fdc35533fd950f3228962f1c52e35dd04839fb517
3776
rs.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Navajo.xml.KRAB
binary
MD5: 52b17947c3ef5bc7e6c74eba4058fc4a
SHA256: d169867d995bafa29cae316211eb3f18669ebdaed201d87e85c26f9629e003f1
3776
rs.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Monokai.xml
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Obsidian.xml
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Navajo.xml
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\MossyLawn.xml
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Plastic Code Wrap.xml
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Mono Industrial.xml.KRAB
binary
MD5: 063f9296f69f3eda946f3b1c7bd01f8d
SHA256: 4de04c7fc5be4084529e47d59f852d6ba9044e30951430bda669e282b3453580
3776
rs.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\khaki.xml.KRAB
binary
MD5: fb32a08efe88708ec6866dc8686e4fae
SHA256: 8fe1e71aec470972f5dc6c09cf4ef04a0e7187b4048ae7f9362ea69ec87ac62c
3776
rs.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Hello Kitty.xml.KRAB
binary
MD5: b5b669467cdd8be7e84d9216e45b94dd
SHA256: fbe409d84bc908048047ddb542860da7493e2eb36fb2396c13b4fdd681af6f1b
3776
rs.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\HotFudgeSundae.xml.KRAB
binary
MD5: 317bc21e64a5f18d7d63587f0220660d
SHA256: 1481d996dac82bcda4eaef3dd7d8df211f7f9c724001ccc830383519bcff64c5
3776
rs.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\khaki.xml
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Mono Industrial.xml
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Hello Kitty.xml
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\HotFudgeSundae.xml
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Choco.xml.KRAB
binary
MD5: ab055c6129060fb4d61e4d6d22008913
SHA256: 86d4221bb912cfb47ab61ba99a6e02bd9a29b699b763f64608b34fac77c54037
3776
rs.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Deep Black.xml.KRAB
binary
MD5: aada3a4e2fd42ca27fc76d1922aa1cf9
SHA256: c3d1d3c2e753151fc814dd7eed0ad802958763bd710ff159de0b144f932d2a75
3776
rs.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Black board.xml.KRAB
binary
MD5: 3d08cf903fb22adef3a7ad03232bbc9a
SHA256: 899fce34e7e7c9010835c7d8e06a6d9dcefbb2029e6cb64559d8bcf2b4dbeb0b
3776
rs.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Bespin.xml.KRAB
binary
MD5: 91d56653f9319c288f1139de13ef5ba2
SHA256: 048d02b49d2b06bf16ec3ae04e777498c95b39c6a321a1c8264f9b9f1151e6bd
3776
rs.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Choco.xml
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Deep Black.xml
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Black board.xml
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Bespin.xml
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Notepad++\functionList.xml.KRAB
binary
MD5: 574f343ba641904eb1c95ee04c2cd579
SHA256: ea02162f85abe9be8c1f88d076cf40f9c55b025a4bc6f5c9b5b8df2b077da71f
3776
rs.exe
C:\Users\admin\AppData\Roaming\Notepad++\plugins\config\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\SystemExtensionsDev\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Notepad++\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\profiles.ini.KRAB
binary
MD5: de05f0c466eecd2084a26b0f7cf77e8d
SHA256: 5600ab6bced930d566cbd93e95e7cda23280882472ddd0d972188eabb66aada9
3776
rs.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Notepad++\contextMenu.xml.KRAB
binary
MD5: 9b7515fa7662a7cf488f714b68ae5ac8
SHA256: 83331e6472504ccc879e39c24b7a7ca1b49c4b34ff1a54640c8f2e5dc91b1a41
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\xulstore.json.KRAB
binary
MD5: 469ecb21e8752e10eba802ce832adfe4
SHA256: 98e195f51cd71b21121999b18968c2a24ba7db1e8eb309811a090ea4c17d0127
3776
rs.exe
C:\Users\admin\AppData\Roaming\Notepad++\plugins\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\profiles.ini
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Notepad++\functionList.xml
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Notepad++\contextMenu.xml
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\xulstore.json
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\webappsstore.sqlite.KRAB
binary
MD5: 6d40fbc60fbd539d33fa6e509e63665d
SHA256: 66e6871db71842506ed95bf4492f9bc461d4785cc9be5c62f4f52526e300e9c9
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\weave\toFetch\tabs.json.KRAB
binary
MD5: d9d5bf752727cfb20c6fcfcca51219e9
SHA256: a71d45d311799b790b7ba25c425882a73eee80c1cddc4018f1144bf50776b273
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\weave\toFetch\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\webappsstore.sqlite
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\weave\toFetch\tabs.json
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\727688008bsleotcakcliifsittsr%.sqlite.KRAB
gpg
MD5: c0c01625f313be5e3e11920b9319d43f
SHA256: 2e7e48f94308f111a0c04b32468caa5512a82ed81d803e4f7a35950eeb750eb1
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\weave\failed\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage.sqlite.KRAB
binary
MD5: 35aeb287e1802daf2a3417fed6223c92
SHA256: 4bd094b3cb67ec10edc63063fac59d5e2ded91fe08181565244d85c9bbc932dd
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\weave\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\temporary\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\times.json.KRAB
binary
MD5: 3644595573f607577983434966837587
SHA256: f0fa16c86b27f031a9f40b2ca7c338b3a01093165fff11abe0ccb5bd5baf9b97
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\weave\failed\tabs.json.KRAB
binary
MD5: acc37be0000382aee110e0b34927b78f
SHA256: d234a7990396181d8b097b38ed5a8fd2a2d99a2a5f7e40845ac561a013a93bc0
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\727688008bsleotcakcliifsittsr%.sqlite
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage.sqlite
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\weave\failed\tabs.json
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\times.json
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3899588440psinninpiFn2g%.sqlite.KRAB
binary
MD5: ef5754a5bfee1c9ba537ac16d8aaa52a
SHA256: 5699d598fec673e42a5985b6be8b69ed6ebb756f95d53faebb0928cc66c4995c
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3899588440psinninpiFn2g%.files\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\727688008bsleotcakcliifsittsr%.files\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3899588440psinninpiFn2g%.sqlite
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3345959086bslnoocdkdlaiFs2t%s.sqlite.KRAB
binary
MD5: d391aa595bff5ef5542ab68c23656fc5
SHA256: e16824bce952e1c79bc6344604336afdc8a176c6c066b8316e0e2747d8885c28
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3345959086bslnoocdkdlaiFs2t%s.files\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\2918063365piupsah.sqlite.KRAB
binary
MD5: e96f8a0629b87bcc5fa5399c7da7bebf
SHA256: 0bb39d4e98a52eee8e3d56ee10660e039c145002d2a4121e6e7dcef5c8edbbac
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3561288849sdhlie.sqlite.KRAB
binary
MD5: e9458840d5f73996c15376e597e0120d
SHA256: 8f80a30f3e1f977cf1eedb8e95b11d18f883824bf0faf84bb7648b07723f70bb
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3561288849sdhlie.files\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3561288849sdhlie.sqlite
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3345959086bslnoocdkdlaiFs2t%s.sqlite
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\2918063365piupsah.sqlite
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1059394878bslnoicgkullipsFt2s%.sqlite.KRAB
binary
MD5: c23802904f88ca7285f1fa857922cd59
SHA256: 578ebc5bb211d86e428adf9bc2d4ae83b81f382955e27deb124db5d562f1b5f6
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1725441852bxlfogcFk2l%isst.sqlite.KRAB
binary
MD5: be1ee4d28ae14f31979dc39243782398
SHA256: 7477a1903eb9353a85de506bd04b6e39aa36602d5bb0cc59659ce5baddead884
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite.KRAB
binary
MD5: 773e7454fce3dacede0c569ef3ff19a1
SHA256: 1d3cedbe6ff69d86f3c59fe071558b91ce122dc6c1b0f30a830485348b66d70a
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite.KRAB
binary
MD5: 6182f7da6975bb4246859cdcfc41b2aa
SHA256: 07271420eab9ef493aaa1a0d5800992c2a3b5a90a19783ae842213e124e1607b
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\2918063365piupsah.files\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.files\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1725441852bxlfogcFk2l%isst.files\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.files\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1725441852bxlfogcFk2l%isst.sqlite
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1059394878bslnoicgkullipsFt2s%.sqlite
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1059394878bslnoicgkullipsFt2s%.files\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\.metadata-v2.KRAB
binary
MD5: d11e2c7076312c872d67f611760165b5
SHA256: 20eef308f329ee469597383e6af72392ff85ccafd5a99864e24f1da568203dfb
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\.metadata-v2
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\idb\3312185054sbndi_pspte.sqlite.KRAB
binary
MD5: ee9358b65c5a1856f01283315cde773e
SHA256: 1f6e956ac22c487a4bdb0c800703502d44ac5eead893a57234baf4cbd6dd2ad6
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\.metadata.KRAB
binary
MD5: f58558dcb4d7877e2c25fc9878418d20
SHA256: b7cb52154584bd3a0b7a5d5364604ab5a55e7dd3f3a17ec4e8dc705c3072b07f
3776
rs.exe
C:\Users\Public\Videos\Sample Videos\Wildlife.wmv.KRAB
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\.metadata
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\idb\3312185054sbndi_pspte.sqlite
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\idb\3312185054sbndi_pspte.files\1.KRAB
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\idb\3312185054sbndi_pspte.files\1
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\.metadata-v2.KRAB
binary
MD5: 111b2d57dabad9465352c3974df47581
SHA256: 0d7d0a74069f1d71cc7f64d1c55bd40f3a69666598f35bb68fead87c6d3cd534
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\idb\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\idb\3312185054sbndi_pspte.files\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\.metadata.KRAB
binary
MD5: 5e79a250b5209765d4ddd6f088e45d47
SHA256: 4c902842570bf9a8ef0207067d21eb472d3626bbe3a812b38da149b7ce9d230b
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\.metadata
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\.metadata-v2
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\idb\3312185054sbndi_pspte.sqlite.KRAB
binary
MD5: 7741418f5897338d68db71978f550329
SHA256: c0b54a78686b3b40bc515a1b4a099118df992438b034c31cb438baa90f9d2106
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\idb\3312185054sbndi_pspte.files\journals\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\idb\3312185054sbndi_pspte.sqlite
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\idb\3312185054sbndi_pspte.files\1
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\idb\3312185054sbndi_pspte.files\1.KRAB
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\idb\3312185054sbndi_pspte.files\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\idb\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\.metadata.KRAB
binary
MD5: 2f28b36117af620edb80d1e1c2ce2926
SHA256: 05c06db86a8c65da6a9cff03215a2b9857ae19ac743f51a71ba9f5b4213491fe
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\.metadata-v2.KRAB
binary
MD5: 9f119be075b1e27c22fa70bc5645eadc
SHA256: eefb3b2308cb5bd688a3887a7e1215e755e28b10be7fed0cb6416fde53c1544f
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\.metadata
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\.metadata-v2
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\SiteSecurityServiceState.txt.KRAB
binary
MD5: 84d9e57a2f9023f2d30d797aad923241
SHA256: ed4eb04334419c882371212ea16a26ecaec86df97716b5024d8858500d0c9bd2
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionstore.jsonlz4.KRAB
binary
MD5: f5533df24781f277cf9b708b67d2eda9
SHA256: 7ba05092f4c48481bcf1b815d0a2359f4c76b754dc439b57a4952c5132673f20
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionstore.jsonlz4
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\SiteSecurityServiceState.txt
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionstore-backups\previous.jsonlz4.KRAB
binary
MD5: df4fbebcc2fa3320abf07c486ca5cba3
SHA256: e9ef1daf61ecd15a7e14071bd989bdb008940948e3f9122566647c9292c2a5ea
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionCheckpoints.json.KRAB
binary
MD5: 5231e5a45f443c1ec4d533ef35f7e0ee
SHA256: d75cc405d56590a4f421ed5c6222730f81c70c2b8cdfbef1d187ab89bc235129
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\search.json.mozlz4.KRAB
binary
MD5: 34dfb87f6b55d97c0c38d5b1830e3e16
SHA256: c58a40fac229a5f2f1de09a5d1b6b46f0d75467e6ce0002bad4294e9c0bb28a7
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionstore-backups\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionCheckpoints.json
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionstore-backups\previous.jsonlz4
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\saved-telemetry-pings\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\revocations.txt.KRAB
binary
MD5: bb31f8fad914dbd5c0aaffe1d8e0a30d
SHA256: e89fe012df30b2945eee0ad9d65fbbf466b3521819fc3e21495a4cf6266f28a7
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\search.json.mozlz4
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\revocations.txt
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs.js.KRAB
binary
MD5: 9d8209d55152b53a271e145d71ead99f
SHA256: 2547c94881de3e86a1b27af88bb0547fd37e561b004c1c69e4b51366a8ff057b
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\pluginreg.dat.KRAB
binary
MD5: 4675cb79f25884b00995d566b701a510
SHA256: ef74047075b05f3dbf68896bed655f3c9fb1223f4ada478a09f424191db4e38a
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs.js
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\pluginreg.dat
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\places.sqlite.KRAB
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\places.sqlite
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\key4.db.KRAB
binary
MD5: 629f1b8ab95da1adc7033dad1e4b454c
SHA256: 161d242f14b89731a71a61317e7af950487065077550af773fa59faac4998d69
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\permissions.sqlite.KRAB
binary
MD5: 7a7e7b13f5485130a20118c95db07de9
SHA256: b02e61016be2cbd74d1893c1004058c433260e97f01fec666e2a9781b00f0d6e
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\minidumps\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\pkcs11.txt.KRAB
binary
MD5: 77a9183fb687dcd7b90357d033864640
SHA256: beb994ab06fea9edf89a1ea7d2c5de5c8fdb66058e12c873dd21699690878cb1
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\logins.json.KRAB
binary
MD5: e5f34614ed4a3322cd56c3c8ca1e64c6
SHA256: 8368d579f00b312cc7bec496cc25fcb77be4109efefde0d17ce47f2698f96134
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\key4.db
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\permissions.sqlite
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\pkcs11.txt
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\logins.json
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\handlers.json.KRAB
binary
MD5: 81ae9b28d71be37741734158bb11f8d4
SHA256: 18a06eea6eca75ffdac3f452d02ba7700824d7de76ba7654628f9d96055105c4
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\1.4.8.1008\widevinecdm.dll.lib.KRAB
binary
MD5: ed4a2de22d2ae45136467459c21ee948
SHA256: 891185797864a2d304bbb667021fedaaeb3a196bbbcb5eb820c0cc2318bdb5aa
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\1.4.8.1008\widevinecdm.dll.sig.KRAB
binary
MD5: 16c6917dd38bdc280e9969f4479120da
SHA256: 606d9871d880ace30d095857bd9f6f9daf821fff992d3b546f32b9e0eedc91cf
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\1.4.8.1008\widevinecdm.dll.lib
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\1.4.8.1008\widevinecdm.dll.sig
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\handlers.json
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\1.4.8.1008\LICENSE.txt.KRAB
binary
MD5: a48541adfb8fe645b6b6109fb287fc6c
SHA256: 9df10b83392b79e0c40fb4e0627c9f4a9735df8684311e10e5ad488eb3d352bf
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\1.4.8.1008\manifest.json.KRAB
binary
MD5: 6fa52f77c141996c8de9f1926890db1c
SHA256: 6aeee6b2b7943a1e1772fc3bba3ee63535591b5aad89b1c953dd475fe577ee36
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\1.4.8.1008\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\1.4.8.1008\LICENSE.txt
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\1.4.8.1008\manifest.json
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-gmpopenh264\1.7.1\gmpopenh264.info.KRAB
binary
MD5: 466710dab697848b799ad6cc086a6e46
SHA256: 191e341f52dac134b39e293e118ba5d6d1b250b864ac08031a81ddbadbc1875f
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-gmpopenh264\1.7.1\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-gmpopenh264\1.7.1\gmpopenh264.info
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\formhistory.sqlite.KRAB
binary
MD5: 62351139a49bef4eff1e5f9b31810e4d
SHA256: d5cacf1f1201311ef2762bd38473ee64d0721730df12d2a616d104ebfc78a8c0
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp\WINNT_x86-msvc\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-gmpopenh264\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\formhistory.sqlite
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\favicons.sqlite.KRAB
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\favicons.sqlite
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions.json.KRAB
binary
MD5: a80c671ae90e5b4afe70a5e42d1a9f02
SHA256: 67ad21d2c87040b5e1deec0033b7648b20f095570f7e1b6216fcfa9f22ab8ad5
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions.json
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\state.json.KRAB
binary
MD5: c7f926674e368a8db77e71f929cee1a1
SHA256: ea8df67efaf01808562eacecf7c87a80121404c8460b893dc64b0130e7835a99
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\session-state.json.KRAB
binary
MD5: 618d3b8834ecfcf2e72366de5e82b0c8
SHA256: 953671c84406a7d4a1e51d98a82850ff7e7e08530037b1fd5c4223f9e779998b
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-09\1536511076670.6fb1a61f-96c8-4004-a260-a8d32e45a07f.main.jsonlz4.KRAB
binary
MD5: c12a65c3a70fd19170cb0153655a1f8d
SHA256: 797d9d6616b9b7accc0b41e3c2bceff751771b5319a398fc08e1862584d7ed42
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\session-state.json
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\state.json
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-09\1536511076670.6fb1a61f-96c8-4004-a260-a8d32e45a07f.main.jsonlz4
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-08\1535454589776.07f73e80-2b12-40ae-97b0-fa87f3167670.main.jsonlz4.KRAB
binary
MD5: 557c55f2eaa08c17c22fc1c0d3e5c0d3
SHA256: ad6bfdda8b794337c31f8760902e4402200ff0c6344b8065e5dbc35263615348
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-09\1536510890757.0bd2c0b0-6051-4678-a27c-37f3c0a0c3bf.main.jsonlz4.KRAB
binary
MD5: e342251fb947c0608aca72ec243c5803
SHA256: ddc089d901fb6125ddfd611232b1ee9631d1ce6c9fc0dcfc65fe76c1c40135cb
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-09\1536510464398.048632c6-c96b-486d-b119-7e1a7a9c9e9a.main.jsonlz4.KRAB
binary
MD5: d5c8064be5c50fb37260dc21e36f081c
SHA256: 17c6ec87b5ecbedef3a741164d7596c4c1d493c8e69a4a27c588dcd9b75a28b4
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-09\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-08\1535454589752.05c13197-8f39-40a1-b976-59f6f9c1cc5f.new-profile.jsonlz4.KRAB
binary
MD5: db003f2f014bdef2e5e55363e1160ea9
SHA256: 0a6c0eedc632bf52c2d3fee3c0ee88ccd5049846a557d9f47a8948c72bc64716
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-08\1535455254239.6a6d1f6c-b378-42bd-83d4-6375a8d83c94.main.jsonlz4.KRAB
binary
MD5: f3257391449d3940ff67441ac8503418
SHA256: 169ee1e5996cff3dbaf024d10927192e8da35b5349bd33fa647b0e21030b37ca
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-08\1535454589777.8901d324-d310-406e-8d96-2ba1529e4bea.first-shutdown.jsonlz4.KRAB
binary
MD5: d563b7d9961b222baf84e304ef0eb11f
SHA256: f333da2114f650df75788befc01e6314b5097a8eef35921ec613497a191c21ac
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-09\1536510464398.048632c6-c96b-486d-b119-7e1a7a9c9e9a.main.jsonlz4
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-09\1536510890757.0bd2c0b0-6051-4678-a27c-37f3c0a0c3bf.main.jsonlz4
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-08\1535454589776.07f73e80-2b12-40ae-97b0-fa87f3167670.main.jsonlz4
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-08\1535455254239.6a6d1f6c-b378-42bd-83d4-6375a8d83c94.main.jsonlz4
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-08\1535454589752.05c13197-8f39-40a1-b976-59f6f9c1cc5f.new-profile.jsonlz4
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-08\1535454589777.8901d324-d310-406e-8d96-2ba1529e4bea.first-shutdown.jsonlz4
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\crashes\events\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-08\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\crashes\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-08\1535454581431.ff499cec-8d4b-47de-a059-a9aea3d69a66.main.jsonlz4.KRAB
binary
MD5: 37bcb0175f92ce40c0026bde28eebe49
SHA256: 808de66c390419464e4a580498d2f05d056bade4503dab675d97fa5714faaf1b
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\crashes\store.json.mozlz4.KRAB
binary
MD5: ce48916c6cd67887abc3f0dc9a728c18
SHA256: 2d45d39564c90541040f8968b5c9c507b0d4bbbaa9f7861f2d7365f41aad9b80
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cookies.sqlite.KRAB
binary
MD5: 33ff4e0971eedcf3e9eb2849fee44a4d
SHA256: 452b2416af4053ff9c45baa0a2e40e7228e802eb37d99c78fa95025931f7dbcb
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\content-prefs.sqlite.KRAB
binary
MD5: fff9bf676649f6deba3a7c88a974d872
SHA256: ce4f5f79c8899e9eb561102b70ad2fdd3b8ca74a31b253df427c3837ae327ee8
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\crashes\store.json.mozlz4
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-08\1535454581431.ff499cec-8d4b-47de-a059-a9aea3d69a66.main.jsonlz4
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cookies.sqlite
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\content-prefs.sqlite
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\bookmarkbackups\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\compatibility.ini.KRAB
binary
MD5: b403533eee8c0b4c6c184ad0b3321bf2
SHA256: 9af9fc77ca72b28356e871a8111cdbf7fd5f7144d35835b7eb3899f14398490b
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cert9.db.KRAB
binary
MD5: a30606de9ed0281ef3db890d92fdf846
SHA256: 04380edb91bb80b0a6ec3dec16dac708b3b3a29c47c2e0f3dd535fe49043ce49
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\blocklists\plugins.json.KRAB
binary
MD5: cc4b3220aeecf4623de9e29e3e459d19
SHA256: 8295b24d30a890f325fcd1f8b849975546a25827cd9dd16623d132d138ebbbbc
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\containers.json.KRAB
binary
MD5: 68f0f0f25d768856dc2d5febd49557a4
SHA256: 8da92bc27b84954d5e9746c3819df4c29c6e53c31ada7df4e3650f58433704c6
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\bookmarkbackups\bookmarks-2018-08-28_14_uZyx1cMFmZ7ZpL4NneCk2A==.jsonlz4.KRAB
binary
MD5: 82ae560ff6ab188d36f84572169adb2d
SHA256: c7af85da28a082925b8ee2a7cbd00cb8978bf242a508f7a1258abdaf1febbd96
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\containers.json
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\compatibility.ini
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cert9.db
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\bookmarkbackups\bookmarks-2018-08-28_14_uZyx1cMFmZ7ZpL4NneCk2A==.jsonlz4
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\blocklists\plugins.json
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\blocklists\addons.json.KRAB
binary
MD5: f06d832c2e8361f161c31fdcc4ae6b59
SHA256: 1a78cf9c63976de6a6a5e55448bed51c11d797c9e6214623e57a0587c7b9d748
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\blocklist.xml.KRAB
binary
MD5: 5dca6d84634e997d3bef43a0facdd3f1
SHA256: 4c48fe96720cbf775e7de43fd7ebac3d150f275c670e9f3803ee9151b29a21af
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\addons.json.KRAB
binary
MD5: 2f0d29d6fddc8b673eb7785973a8fd82
SHA256: 0194a8aaef5d6b55f7ba603107355d05d3ade176357c2d69413b302eaecf35e4
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\addonStartup.json.lz4.KRAB
binary
MD5: a0e80cee1723ec3dc4828b9b10cddc23
SHA256: 2fc8cfe50f21cae08ce82e1624b2e785b5924ccc181b823267bddd3a5b5b1dee
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\blocklists\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\blocklists\addons.json
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\blocklist.xml
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\addonStartup.json.lz4
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\addons.json
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Word\STARTUP\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Word\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Templates\Normal.dotm.KRAB
binary
MD5: 57353df063fe39832538c14232eed739
SHA256: 4e01ad55dcf83ee3c13fab82b50354beb9b4c15a97013b4a1d68e2807d3d8d25
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\UProof\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Templates\NormalEmail.dotm.KRAB
binary
MD5: 1fb379be43e61856c55910b443fd702f
SHA256: 958179a394959a78645085064aec774ed68d07d5122399750d0b8965dcdb9bce
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Vault\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Crash Reports\InstallTime20180807170231.KRAB
binary
MD5: e27fe735c711cf9b11e71ab685cc218a
SHA256: 5cd4f5ff88608e08e5d241dfbff3d78f0017100c57dc8a549cf0796941c5afca
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Extensions\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Crash Reports\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\UProof\CUSTOM.DIC.KRAB
binary
MD5: b77eac2efcbce0072d84984bc9da352c
SHA256: 31f8f6d60a9b6cf089ba00da17c3ec968a43d22905f5e18300d491e55c836e11
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Pending Pings\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Crash Reports\events\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Crash Reports\InstallTime20180807170231
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\UProof\CUSTOM.DIC
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Templates\NormalEmail.dotm
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Templates\Normal.dotm
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\Keys\ECCD4BA46722CB4F92060701865DDF09D8AF68B4.KRAB
vc
MD5: c07d3dfe78cf7a4caae2e85e16cd8820
SHA256: 93d9de84a828b83f7bb641e0e9bc422db849ee62a80dda2e86cde75eee1c6066
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Templates\LiveContent\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\E02357FC7708441D4B0BE5F371F4B28961870F70.KRAB
binary
MD5: 8cb621d751f388d9f14a0d7a51ae1b0a
SHA256: b1f3b590627e1da50a9c43b58f28a3ae2d8f44dd340a155047d98ffc172d6aa1
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Templates\LiveContent\Managed\Access Parts\1033\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Stationery\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Templates\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\CTLs\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\CRLs\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Speech\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Templates\LiveContent\Managed\Access Parts\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Templates\LiveContent\Managed\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\Keys\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\Keys\ECCD4BA46722CB4F92060701865DDF09D8AF68B4
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\E02357FC7708441D4B0BE5F371F4B28961870F70
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\live#3agabriel.radrigos\main.db-journal.KRAB
binary
MD5: 9bd8d9ccfcdd0f274a0168855f2c308b
SHA256: cced27e5b3ae248dd3365bab2ddf83bb3acd09c5e4130db86715b49eaed2ba4a
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\slimcore-0-4223384469.blog.KRAB
binary
MD5: 871fae73d6ca624450bac37fefccf186
SHA256: 7dd6a9c9ea1c4502e579e9a7304fa6762a80d932c9b8ff6237361c7b5ba7df0c
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\live#3agabriel.radrigos\config.xml.KRAB
binary
MD5: d4a0ace4af66acef8b095f202c95b6b6
SHA256: c0c8883edbfff5fc3a171989949bf1e5826a2f4068a5759c82cc112c943a14af
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\live#3agabriel.radrigos\main.db.KRAB
bs
MD5: 8144881d230796bb4dae6b2e2f390bdb
SHA256: 75291690658351e50fd827c31c99cbaf0ff4f621fc8e75fd351e4a7cfd4dac97
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\shared.xml.KRAB
binary
MD5: d8a6d446e4a799d32714666349949a9a
SHA256: a09452c06043add0e47ab0f1c6898e8b24956490ca4fd08dfe43c9a3b56cf2fd
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\live#3agabriel.radrigos\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\slimcore-0-4223384469.blog
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\shared.xml
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\live#3agabriel.radrigos\main.db-journal
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\live#3agabriel.radrigos\main.db
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\live#3agabriel.radrigos\config.xml
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\DataRv\offline-storage.data-wal.KRAB
binary
MD5: c4fad600aaee9442ddf6d61553f6f71e
SHA256: 36aa49db13a5eadaf5dda6485ec75ade81c6ab27430afe769f2ac64859d1e382
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\DataRv\offline-storage.data.KRAB
binary
MD5: 70ceac70c2d19ab054b4edfa9120f8db
SHA256: 9d0d564dd537236a0fa33f4bc790409ad3796d94570d7ff43857f20528f35759
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\DataRv\offline-storage.data-shm.KRAB
binary
MD5: 0eb0fb4181bf28d0d792bfa6728aea30
SHA256: 56a784e8f92ed48885aa14e191f626cb20e26404d7ad51d27c08599ec431bf87
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\DataRv\offline-storage.data-wal
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\DataRv\offline-storage.data-shm
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\QuotaManager.KRAB
binary
MD5: 1d1c67e82310048b841eb1470e13c5c7
SHA256: 243d5f485a92dbf17165f0691d16ab001ba7731166206c53761a5ca3768faab1
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Preferences.KRAB
binary
MD5: 2597b358aa222ce66a84b96231dff845
SHA256: 8869cf241228ba6fe0b3cd32cc5340962e726d7e4d38afc46e0fd8512cc6106f
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\Skype_MediaStackETW-2018.34.1.3-UVA-x86release-U.etl.KRAB
binary
MD5: 3bce59a00da2a14c74e8e74d4e6d816a
SHA256: b820c778e1e6dc1ca17651cd1bacc224899e136bb87f572eeb66f9a504b04bf2
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\Skype_MediaStackETW-2018.34.1.3-UVA-x86release-U.etl.bak.KRAB
binary
MD5: 647f2c28b9c6aef06d6dbf3b291b91f7
SHA256: d2a961c060072ba2b5e34b6ad5873578beaae7df29452d3f3d4e635607ea427c
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\DataRv\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\settings.json.KRAB
binary
MD5: 5e3fc6782ec436d482fb5b9de2467950
SHA256: a814f1cd2369b22a076e7c2a365d5061cd95b7073ba4642cf29070808008c288
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\settings.json
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\DataRv\offline-storage.data
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Preferences
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\Skype_MediaStackETW-2018.34.1.3-UVA-x86release-U.etl
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\Skype_MediaStackETW-2018.34.1.3-UVA-x86release-U.etl.bak
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\QuotaManager
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\Skype.msrtc-1-1870167131.blog.KRAB
flc
MD5: 8e6686c43761722272ed34408fbe72f0
SHA256: 36ef19ed29f2d2028a3ba89cde826dcdc150baa17eb595cd4ca8bd4cd2b38404
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\Skype.msrtc-0-2576771366.blog.KRAB
binary
MD5: 56a4e7adb530201fda83d73ac039e85a
SHA256: faad17dc9cb9e06187fadb94805d058bf8deda8f9fccd3e2f0a09c99d82681c3
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\MANIFEST-000001.KRAB
binary
MD5: 5882d258d59a10bf28cd90b4a571a5ab
SHA256: 988406c4ebf6788e6e1c93c41ab5ff764243a12217d8e10651db97383b7dd67c
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\LOG.KRAB
binary
MD5: d30a9e924af2a2364f7ad3fa112285e6
SHA256: a014bf6c9098df307fd1d27f119276ddbace09c9ddd2df4aead5a5f039af5466
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\logs\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\CURRENT.KRAB
binary
MD5: eaacb9e8f882a46196d31d2be7cb0943
SHA256: 35156c5e1424234a8540f4da234db21d602dbe73a3233dabee51dd2b1f7536ee
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\LOG.old.KRAB
binary
MD5: 9679e6094a3ae1a6e38624069cd251d0
SHA256: 080f17e2b69eb6568cabd61521fad7b03a3111e1b4d7202712859bdfa76ecb1c
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\Skype.msrtc-1-1870167131.blog
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\Skype.msrtc-0-2576771366.blog
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\MANIFEST-000001
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\CURRENT
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\LOG
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\LOG.old
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\000018.ldb.KRAB
binary
MD5: 751f418c0e857b4016225f33bf17aa50
SHA256: efefd0bbc5d434488a902d4180fe2fd85c39f7407c0f6ffd92b8bb035a8eae90
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\LOG.old.KRAB
binary
MD5: 73184c95a0ac34f1033535f850c4aeb2
SHA256: ae86a622b588773209bf07c34bbade126892e22de001467c1f92071898534a3f
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\000017.log.KRAB
binary
MD5: 5189a1b79682e64387fe0f79c13a1424
SHA256: 6b12820d6a641a73e6da42841e7fc5066edc71a96f197a008bdb3e6de7a65391
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\MANIFEST-000001.KRAB
binary
MD5: fa2f2013d072589242929347d3ebf39c
SHA256: b1a073ee816de8e20dacd3019b7270342eb7ed82f38ef9ae544843b8fe03ae03
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\000005.ldb.KRAB
binary
MD5: eb9085107f77f331d4fb1328022d77ac
SHA256: 8da512f454a1b8dd7c0c1ca271e6c20baa942ff6321de73b4cf5621dd7d0fec8
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\LOG.old
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\000005.ldb
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\MANIFEST-000001
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\000017.log
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\000018.ldb
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\000003.log.KRAB
binary
MD5: 189b428d3bd5a140ae3cec07bf180294
SHA256: 0ad999f5c80a50fba7b7fdeabf5a77c362bb6782926a106c6a106b24d7fb7194
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\CURRENT.KRAB
binary
MD5: ee03bb4b28c0c8d22e6ac9e1970c13e2
SHA256: dfb80ee0c8be04b20d28bb7c68ffbf9e5b7bc0999af92047a296a62afc044352
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\LOG.KRAB
binary
MD5: 4e5a1867926f60a119313be30d38951d
SHA256: bfb5230dd3285b13691477582a64e2d4e59b868b7973bc070dd45f047c369eb6
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\LOG
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\CURRENT
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\000003.log
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\device-info.json.KRAB
binary
MD5: 0afe19618b2b21be4d22f1366f7a5b7d
SHA256: b6e9e534dd713ad1bbc74f32600519237b87f4b5c98e5f93071e186483ce1d1c
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\dictionaries\en-US.bdic.KRAB
binary
MD5: da896d152074382de0f5c3c8e9c0a914
SHA256: 3553d83576ae597199c0a4eadda95abbc47eb95489f2bb2b7eece12ba51b9cac
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\dictionaries\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\databases\Databases.db.KRAB
binary
MD5: f80da86a8c5b8e64cb012c11e734d8c7
SHA256: 89b434b0f717be32cae6d0b7a9bb3ddc4229b1c350a0c6cdac5dd12b89384f83
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\ecscache.json.KRAB
binary
MD5: f436ee5b90e7f40e9e42ef936996d0d2
SHA256: 6a458bd3a3443c569e4b6ce15f71e5c91636a28a958b40571382aff840638cf9
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\ecscache.json
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\dictionaries\en-US.bdic
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\device-info.json
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\f_000004.KRAB
binary
MD5: 777f8c1b7e7303e7fd1ef55de016a646
SHA256: 3a89000a23979971c0cdac07dc260a5982c21437fc2a69dca22698d70e012114
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\databases\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cookies.KRAB
binary
MD5: a5c40806c13d5a4ed5b53fa70836717f
SHA256: e875f384821c63f8b56b2f600441d8b971940f31d281eb1f7499a96401db955a
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\index.KRAB
binary
MD5: 1b34a9f687284727f87bcbd30e5f7310
SHA256: e0d08e968fcdb98cfcd6a7b3668950cc9a55284087dd1212c9fc4cf5ce626b60
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cookies
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\f_000004
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\databases\Databases.db
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\index
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\f_000002.KRAB
binary
MD5: 7991bb57560d308de015e7a4f8763386
SHA256: c7dbfe7f5dd4ef66506259e53a279d812a496fca67647d57e8f455372ce2f1a8
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\f_000001.KRAB
binary
MD5: f2804a2d81cc99a8aadac7d20a6f60fd
SHA256: 278b6df94d8a6ac0ce3ae5bf34074fee84d43985308d1e8fc741fa55398f857b
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\f_000003.KRAB
binary
MD5: 39fbb57ce354811e7fd488c60be5bbb3
SHA256: d1a79734d28435401592c3467a7e52e798dd982a59c44f11bf0c4c998c47df47
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\f_000001
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\f_000003
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\f_000002
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\data_3.KRAB
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\data_3
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\data_2.KRAB
binary
MD5: fb4d0e02d822c36be901d9e656f2ce28
SHA256: 211c46760c3aa488508401a5edfe958e64d6dd3b46b493437c634a73c45eddba
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\data_2
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\data_1.KRAB
binary
MD5: 983c10a9caa9daf2b01143faa376f255
SHA256: 3b13bdecdf3a6bc0789ac46eb1594a7e6fa15043db0c074b18f6b3fdbd9c10f6
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\data_0.KRAB
binary
MD5: 62e4e6046aab725a0c6c0594ffc75645
SHA256: f9c9f98ace840fc946b99b83bdb807a795af53981d7867dfeb144f3413048419
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\data_1
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Publisher Building Blocks\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Signatures\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Publisher Building Blocks\ContentStore.xml.KRAB
binary
MD5: 954b9218569391b9d9e60b1d897bea8f
SHA256: 9db5728c6ec217da357293385081dde2589253d552e3b613d78036a9bd4617a7
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\data_0
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Publisher Building Blocks\ContentStore.xml
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\PowerPoint\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-1000\Preferred.KRAB
binary
MD5: d06141b1b91ef1fe130b9e7ed044f21f
SHA256: 2284adafcf9c95adcfd4c6f0324c5d0476d0ab7f11eabff78867a2f721c66893
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\test.xml.KRAB
binary
MD5: 8d065c61dac335f31a2bb5eb7860138a
SHA256: 134f7fd3b4cbd6fa649e4f6f1acf5ded8a971c3ba7c318171479647e9c2a9715
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-1000\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-1000\54ba308a-6a9a-4e0e-b137-b89d3579498b.KRAB
binary
MD5: be0ccab82ce6f82cef7edad7de8534aa
SHA256: 7b3e77e6b77a16f6a7084811d1ed366d28c604d40a8f04a066208b6acab03efe
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-1000\29fd2168-360f-422a-a685-e6961ea74ba8.KRAB
binary
MD5: 6eac32946b008bd46a0ad442e1b8bb37
SHA256: d388572d64fba233f8bf690ca0fc63147275b49733c0bbdfd2e98e66353850c4
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Publisher\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Proof\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\CREDHIST.KRAB
gpg
MD5: 9ef1cb486cbb21d143e987b2e9dc34c8
SHA256: 992c69a9b5b0b42cc25bac522f852c933a11acbc0d87c6a079fb8048372f4803
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\CREDHIST
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\test.xml
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-1000\29fd2168-360f-422a-a685-e6961ea74ba8
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-1000\Preferred
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-1000\54ba308a-6a9a-4e0e-b137-b89d3579498b
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\OneNote\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\OneNote\14.0\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\Outlook.srs.KRAB
binary
MD5: 8e457204eb5443ce018d1b2ed914f3eb
SHA256: ec445a04f5bd744dee9da6ad10e5306ab02f945b2e591fdbe2177f07a0f737e8
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\NoMail.xml.KRAB
binary
MD5: 8ce6d0d68ce81d988e92dfbcedbec7cf
SHA256: f71520e0b091b0eb6071c05571941faae6fdf25d5e5eb3b77a19b5246c93df4b
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\test.srs.KRAB
binary
MD5: d3ad1bcaaf0b53ff04d1bd246f2581f6
SHA256: ce16d23fd8b9e47fd1aba4cc0eed919aba401a621ebe4264b844d0a37936b08c
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Office\Recent\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\Outlook.xml.KRAB
binary
MD5: 3055df85d9113aa7ce1f956972911d29
SHA256: 45297a368f1509837d3289590354dded280da8b23aaed26414b85af92e59e934
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\OneNote\14.0\Preferences.dat.KRAB
binary
MD5: d206d0d39432b4601b05d0c6fee7a9a5
SHA256: bbb21ba824ca794aec8543e71482281ea38af3e85d77458d46960059a8259541
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\Outlook.srs
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\Outlook.xml
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\NoMail.xml
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\OneNote\14.0\Preferences.dat
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\test.srs
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\MMC\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Network\Connections\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\MMC\taskschd.KRAB
binary
MD5: f073249ada9dc0348f212c9c47c755f2
SHA256: dbaa5aec960b6272695ffbacfc7ea03f51c8ea8257ee3d51b6d78e717882fddb
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Office\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Network\Connections\Pbk\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Network\Connections\Pbk\_hiddenPbk\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Network\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Office\MSO1033.acl.KRAB
binary
MD5: 8184d299d6e392b86b1ca26c97ad1a90
SHA256: 589995833f297f6c08561da0765832c0fac35491d90264010ac82d67ef3956be
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\MMC\taskschd
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Office\MSO1033.acl
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\HTML Help\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Excel\XLSTART\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Excel\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Internet Explorer\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\HTML Help\hh.dat.KRAB
binary
MD5: bd0669f2ae3d6005dc7f890505b95ddb
SHA256: 162902ad2c3f2886c3a6122923e94d14f5c468b251dc67ec9e5a295c8fd0c706
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Document Building Blocks\1033\14\Built-In Building Blocks.dotx.KRAB
binary
MD5: 74e00fc0f33e6b5bd025560c7bf62f17
SHA256: acb4c194227804e3f20de5776cf10d403a37963090c32c993c856918b62e3136
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\HTML Help\hh.dat
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Document Building Blocks\1033\14\Built-In Building Blocks.dotx
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Document Building Blocks\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\c43c9d3341c1ddc712bbe39db3c78fa5_90059c37-1320-41a4-b58d-2b75a9850d2f.KRAB
binary
MD5: 52ddc6ad600016a91e2a0ebfbb0d2f5a
SHA256: f36f633b08dde450449727e32f6d2fc2450ee8aa1174a1efe29ed2535bfc2d58
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\e3f86d7936454598ef98443d4fd3260d_90059c37-1320-41a4-b58d-2b75a9850d2f.KRAB
binary
MD5: 68af133a815b4f6a7f34bd349b8dc8e8
SHA256: 63914b72ea561058a250aff4ea831925a0f20c2145a682cfe7a3142fdf72fe09
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\a551dda6b1d5ee0d0c4637af6c004413_90059c37-1320-41a4-b58d-2b75a9850d2f.KRAB
binary
MD5: 03c42ff66f7f1b0f25bc4261be3fa20d
SHA256: a026a38d8a50bf70d374d7a8b977bcdd58729110fd35ef122fbceef4f92b1267
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Document Building Blocks\1033\14\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Document Building Blocks\1033\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\e3f86d7936454598ef98443d4fd3260d_90059c37-1320-41a4-b58d-2b75a9850d2f
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\c43c9d3341c1ddc712bbe39db3c78fa5_90059c37-1320-41a4-b58d-2b75a9850d2f
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\a551dda6b1d5ee0d0c4637af6c004413_90059c37-1320-41a4-b58d-2b75a9850d2f
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\FileZilla\queue.sqlite3.KRAB
binary
MD5: 3f6b2b031ab0561163985cfc91d03438
SHA256: d47c90e5680271c7943cebd62cc8d041797d8763bbea75c7e7f121127cdcf56c
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\1f91d2d17ea675d4c2c3192e241743f9_90059c37-1320-41a4-b58d-2b75a9850d2f.KRAB
binary
MD5: ea98ab320cae5b6a111256cd9ca687c1
SHA256: 30aefd6ebd3d6ca6e013edf0ee57b8556c30cc31ab80fdea37441976a18b522b
3776
rs.exe
C:\Users\admin\AppData\Roaming\Media Center Programs\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\7be1242ebc44e45985bd1ffa382e997c_90059c37-1320-41a4-b58d-2b75a9850d2f.KRAB
fli
MD5: 2cb92fd0339440571680e134372a34bc
SHA256: 7339d403ca421980614e2fe7d4f4ede582d0946c3e3bc783b632512d852e45f1
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Credentials\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\FileZilla\layout.xml.KRAB
binary
MD5: 0840864b0daa3fac3e81441ce5c09e22
SHA256: 50cdd9be34c9f490212f2cc1a73ed4e9b105a541356d6598c581195dccb00362
3776
rs.exe
C:\Users\admin\AppData\Roaming\Identities\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\0f5007522459c86e95ffcc62f32308f1_90059c37-1320-41a4-b58d-2b75a9850d2f.KRAB
binary
MD5: d0c1e85a3071baeb97072c2b3ef16708
SHA256: 0d329c621f587fde72b6ce6526e793bd137d9f7f9fcffdae963c46e0e4b89560
3776
rs.exe
C:\Users\admin\AppData\Roaming\Identities\{E4CE17A7-FC47-4CD1-8FF6-45436C8F45DB}\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\AddIns\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\0f5007522459c86e95ffcc62f32308f1_90059c37-1320-41a4-b58d-2b75a9850d2f
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\1f91d2d17ea675d4c2c3192e241743f9_90059c37-1320-41a4-b58d-2b75a9850d2f
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\FileZilla\queue.sqlite3
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\FileZilla\layout.xml
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\7be1242ebc44e45985bd1ffa382e997c_90059c37-1320-41a4-b58d-2b75a9850d2f
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Adobe\LogTransport2\Logs\ulog_HeadlightsOptinProductFamily_HeadlightsOptinProduct_00000000-0000-0000-0000-000000000000_dc2ece58-8a8b-40bf-98c2-48039a3392bd.log.KRAB
binary
MD5: ec6bb4fec562fac3731545d196af9bc5
SHA256: 64a7099da0bf0b700fb504da4e8c93224e70181ce761b541cd81ee25d124bc9a
3776
rs.exe
C:\Users\admin\AppData\Roaming\Adobe\LogTransport2\LogTransport2.cfg.KRAB
binary
MD5: bc012c725f0c678af10361eed3d732b7
SHA256: f74072fcaf742f154797e8c2799450bab5d299733c93a1ad0228f0d46dc244aa
3776
rs.exe
C:\Users\admin\AppData\Roaming\Adobe\Sonar\Sonar1.0\sonar_policy.xml.KRAB
binary
MD5: f2f02bde09e16ea6dbfebcc2ffdfaa54
SHA256: 1133fc9e27485e1862c24368be5ac92740052242d6b6db60b47e1d3528949c3d
3776
rs.exe
C:\Users\admin\AppData\Roaming\FileZilla\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\FileZilla\filezilla.xml.KRAB
binary
MD5: 15187539128e4d7e3f9876bfbe911a99
SHA256: 93bf3a795d08ec9d47cb803369f0ebaa30414c8f166f4ba3d76733bf1088b7ae
3776
rs.exe
C:\Users\admin\AppData\Roaming\Adobe\Sonar\Sonar1.0\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Adobe\LogTransport2\Logs\ulog_AcroARM2_ARM2Update_2274f67c-7a7f-45e3-a23e-aa35d5b91e00_fea03e67-af51-4fcb-b57f-c238867edb9b_0.log.KRAB
binary
MD5: fb494af5b9857045b4bde0370aab93a0
SHA256: 30ed3432728524f92e3cafb4dff86d0941d4583c432f8ce3e9d71e29638de473
3776
rs.exe
C:\Users\admin\AppData\Roaming\Adobe\Sonar\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Adobe\LogTransport2\Logs\ulog_AcroARM2_Reader_2274f67c-7a7f-45e3-a23e-aa35d5b91e00_02f147fa-0489-4885-b993-ed9936fcacc0_0.rdy.KRAB
binary
MD5: 7f4bd27bb08c60da3e71086282132e0c
SHA256: f559743c122f6fb911b86241647985b9c78135059fb9511a2d0880d3c5c49f6e
3776
rs.exe
C:\Users\admin\AppData\Roaming\Adobe\LogTransport2\Logs\ulog_AcroARM2_ARM2Update_2274f67c-7a7f-45e3-a23e-aa35d5b91e00_fea03e67-af51-4fcb-b57f-c238867edb9b_0.log
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Adobe\Sonar\Sonar1.0\sonar_policy.xml
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Adobe\LogTransport2\Logs\ulog_HeadlightsOptinProductFamily_HeadlightsOptinProduct_00000000-0000-0000-0000-000000000000_dc2ece58-8a8b-40bf-98c2-48039a3392bd.log
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\FileZilla\filezilla.xml
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Adobe\LogTransport2\LogTransport2.cfg
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Adobe\LogTransport2\Logs\ulog_AcroARM2_Reader_2274f67c-7a7f-45e3-a23e-aa35d5b91e00_02f147fa-0489-4885-b993-ed9936fcacc0_0.rdy
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Adobe\Linguistics\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Adobe\LogTransport2\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Adobe\LogTransport2\Logs\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Adobe\Headlights\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Adobe\Flash Player\AssetCache\J7D4H966\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Adobe\Flash Player\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Adobe\Flash Player\AssetCache\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\CE338828149963DCEA4CD26BB86F0363B4CA0BA5.crl.KRAB
binary
MD5: c10c6e1d92fae70774804e2c624dd89d
SHA256: 2b636242dc63ddf3d39c03a88f73da1116f84badb4370f6329e057db3e02950f
3776
rs.exe
C:\Users\admin\AppData\Roaming\Adobe\Flash Player\NativeCache\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\CE338828149963DCEA4CD26BB86F0363B4CA0BA5.crl
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\0FDED5CEB68C302B1CDB2BDDD9D0000E76539CB0.crl.KRAB
binary
MD5: 53de5e3d814114dd918caef53b807574
SHA256: a4734aa3d981d87e0ca4f9dde8ca9ed9990d6debb4f6d85a813cda41c82cca53
3776
rs.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\0FDED5CEB68C302B1CDB2BDDD9D0000E76539CB0.crl
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\Security\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\Security\addressbook.acrodata.KRAB
binary
MD5: 2cadcb76430f6fb9a60990d23acc7937
SHA256: 12eb1a4906e156b0e2a4024b0451b4bc080514bff639f1de11ab6e47c6d8ee14
3776
rs.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\Security\addressbook.acrodata
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\JSCache\GlobSettings.KRAB
binary
MD5: 7512840cf71b981bf0fc83c06d70b206
SHA256: 40243099918f4985530c1851b5241de509d4a46b56ae959d24b3f864d04b64e3
3776
rs.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\JSCache\GlobData.KRAB
binary
MD5: 1fad908b8035f91b321d9343d261c5b6
SHA256: d1e797ecfa8d165cb2303704310a41f9717bc4ebe829255ee0dd85878fd05560
3776
rs.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\JSCache\GlobData
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\JSCache\GlobSettings
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\Forms\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\JSCache\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Adobe\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\.oracle_jre_usage\90737d32e3abaa4.timestamp.KRAB
binary
MD5: 64138ef2963e16949b30c6dd4bb48122
SHA256: dc538c9832db695a2744128d548c01a11560630c580e571a59492f15571bcd25
3776
rs.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\Collab\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\.oracle_jre_usage\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778
3776
rs.exe
C:\Users\admin\.oracle_jre_usage\90737d32e3abaa4.timestamp
––
MD5:  ––
SHA256:  ––
3776
rs.exe
C:\$Recycle.Bin\S-1-5-21-1302019708-1500728564-335382590-1000\KRAB-DECRYPT.txt
text
MD5: a5cefdd290eee1cf91c627e54e0acaa0
SHA256: 85dd750f0cec79dfaefde7a585ada1812dee92bb6c31f669e6da7d3a0915a778

Find more information of the staic content and download it at the full report

Network activity

HTTP(S) requests
3
TCP/UDP connections
4
DNS requests
2
Threats
0

HTTP requests

PID Process Method HTTP Code IP URL CN Type Size Reputation
3776 rs.exe GET 302 217.160.0.234:80 http://www.billerimpex.com/ DE
html
malicious
3776 rs.exe GET –– 52.29.192.136:80 http://www.macartegrise.eu/ DE
––
––
malicious
3776 rs.exe POST –– 52.29.192.136:80 http://www.macartegrise.eu/static/imgs/hedethkefude.png DE
text
––
––
malicious

Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID Process IP ASN CN Reputation
3776 rs.exe 217.160.0.234:80 1&1 Internet SE DE suspicious
3776 rs.exe 217.160.0.234:443 1&1 Internet SE DE suspicious
3776 rs.exe 52.29.192.136:80 Amazon.com, Inc. DE whitelisted

DNS requests

Domain IP Reputation
www.billerimpex.com 217.160.0.234
malicious
www.macartegrise.eu 52.29.192.136
malicious

Threats

No threats detected.

Debug output strings

No debug info.